Skip to content

TA488 Deploys Unknown OWAReaper Backdoor Against Mail Servers

In brief: TA488 infects mailboxes with OWAReaper via CVE-2026-42897 in Outlook Web Access through incidental email opening and secures persistent access via browser local storage and stolen OAuth tokens.

The Russia-linked hacker group TA488 has been distributing crafted emails since July 2026 to US and European government agencies as well as companies in critical sectors. A vulnerability in Outlook Web Access is sufficient for infection with the new OWAReaper backdoor, which runs entirely in the browser and compromises mailboxes long-term.

Security researchers from Proofpoint have documented a new attack campaign by the group TA488 (also known as Void Blizzard or Laundry Bear). Since 22 July 2026, the group has been distributing manipulated emails to government agencies in the US and Europe as well as companies in telecommunications, financial services, hospitality and aerospace. The emails disguise themselves as automated information services on innocuous topics such as semiconductor supply chains or tourism statistics and contain neither links nor classic attachments. This mechanism makes them difficult to detect, as affected users rarely report the messages to security teams.

The attack exploits CVE-2026-42897, a Cross-Site Scripting vulnerability in Outlook Web Access. Embedded JavaScript code is automatically executed when the email is opened in the webmail client. Proofpoint suspects that TA488 exploited the vulnerability as a zero-day: initial campaign infrastructure was created as early as March 2026, while Microsoft did not publish the official patch until May 2026.

The OWAReaper backdoor runs entirely in the reading pane of Outlook Web Access and thus leaves no traces on the infected device. The malware captures credentials through invisible input fields populated by browser autocomplete and secures persistent network access through three independent persistence mechanisms: an encrypted copy in the browser’s localStorage, stolen OAuth tokens via compromised Outlook add-ins, and a hidden iframe in cached messages of the offline database. By stealing the OAuth tokens, the malware also grants the default user of the respective Exchange tenant owner rights on all mail folders – this theoretically gives all authenticated users of the affected organization access to the compromised mailbox until the permission is specifically removed.

Proofpoint classifies OWAReaper as a further development of the ZimReaper malware known from earlier campaigns. The omission of mass exfiltration of entire mailboxes suggests increased operational security awareness. For mitigation, Proofpoint recommends affected organizations to revoke Exchange Web Services tokens of affected add-ins, remove folder permissions granted to the default user in Exchange, clear the offline database and used localStorage keys, and block or alert on outbound connections to known command-and-control servers of the group.


Source: www.it-daily.net · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: