Russian state-run hacker group Laundry Bear, also referred to as Void Blizzard, is exploiting vulnerabilities in Alternate Outlook Internet Entry in e-mail campaigns to ship a classy backdoor referred to as OWAReaper.
E mail safety agency Proofpoint found the marketing campaign every week in the past, focusing on quite a lot of organizations, together with U.S. and European authorities companies and firms within the telecommunications, monetary, hospitality, and aerospace sectors.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that enables arbitrary JavaScript execution within the browser context when a person opens a specifically crafted e-mail within the Outlook Internet Entry (OWA) app.
Beforehand, the identical hacker exploited one other XSS vulnerability (CVE-2025-66376) as a zero-day in Zimbra e-mail servers to distribute ZimReaper malware that steals e-mail communications, two-factor authentication (2FA) codes, utility passcodes, and passwords.
Proofpoint researchers confer with this sort of XSS exercise on webmail platforms as “half-click exploits.” It’s because the exploited vulnerability is triggered just by a person opening a malicious e-mail.
Improper HTML sanitization
In a brand new report in the present day, Proofpoint describes Laundry Bear’s new half-click exploit marketing campaign as a “important enchancment within the group’s expertise and capabilities.”
Primarily based on Microsoft’s Could 14 advisory relating to the CVE-2026-42897 flaw in OWA, risk actors have been already exploiting it as a zero-day.
This safety difficulty could possibly be exploited to trigger the server to improperly sanitize HTML code inside the message physique and execute JavaScript when the e-mail is opened.
Based on Proofpoint, Laundry Bear, which the corporate tracks as TA488, created the assault infrastructure for the OWAReaper marketing campaign in March, almost two months earlier than Microsoft’s alert.
In latest noticed exercise, risk actors used messages on matters of curiosity to their targets, together with provide chain evaluation, analysis updates, and efficiency indicators for tourism and fuel markets.
“As a result of the topic line and invitation are commonplace, focused customers might open the message, skim it, after which ignore the message as junk as an alternative of reporting it, particularly given the shortage of suspicious URLs or attachments.”
Proofpoint explains that the attackers took benefit of the improper sanitization difficulty to incorporate malicious code within the messages, including HTML and JavaScript to the malicious messages.
The e-mail contained an embedded JavaScript loader and a Base64-encoded payload blob after the “#” character within the social media icon URL.

Supply: Proofpoint
The exploit supplies a backdoor that researchers are calling OWAReaper, which researchers describe as “probably the most subtle backdoor delivered by way of a half-click exploit.”
Evaluation revealed a “set of delicate persistence mechanisms” that turned out to be an evolution of the ZimReaper malware noticed in assaults towards Zimbra e-mail servers.
“OWAReaper runs solely within the Outlook Internet Entry (OWA) studying pane. When run, it makes use of Outlook APIs to rewrite emails on the Alternate server to take away exploit content material. It additionally disables OWA pop-ups and right-click performance whereas it’s operating,” Proofpoint stated.
The malware collects e-mail addresses, usernames, and Outlook settings of compromised accounts. It additionally makes an attempt to steal entry credentials by creating hidden components within the Doc Object Mannequin (DOM) and ready for the browser to routinely fill in these components.
Lengthy-term persistence mechanism
Proofpoint researchers discovered that TA488 (Laundry Bear, Void Blizzard) was capable of preserve entry to focus on mailboxes even when the system was restored from a clear picture or credentials have been rotated.
Menace actors accomplish this by means of OWAReaper. OWAReaper checks for put in Outlook add-ins with ReadWriteMailbox permissions and makes use of them to steal OAuth tokens by means of GetClientAccessToken operation requests.
“It then calls UpdateFolder to grant owner-level permissions to the ‘Default’ person (a low-privileged preset alias included in each Microsoft Alternate tenant) for all mail folders,” the researchers defined.
This permits an attacker to entry the mailbox from any authenticated account inside your group.
As a result of mailbox permissions are configured on the server aspect, altering the compromised person’s credentials or reinstalling the affected system is not going to revoke the attacker’s entry.
OWAReaper implements a second persistence mechanism by enabling caching and injecting a malicious iframe into the HTML of messages saved in OWA’s offline IndexedDB.
“This iframe is executed each time the sufferer opens a malicious e-mail from the cache,” the researchers stated.
Two of all
The malware helps two command and management (C2) mechanisms to obtain directions from the attacker. One in all them makes use of GitHub commit messages as a communication channel.
Each 24 hours, the malware queries GitHub’s Commit Search API for encrypted messages that match a selected format and comprise the goal’s e-mail tackle.
OWAReaper may parse emails delivered to focus on mailboxes. Verify the message physique in IndexedDB. {target_email_address}{area}{Base64text} construction.
Laundry Bear additionally used two strategies to steal knowledge. The first methodology is utilizing HTTPS with an AES-CTR encrypted URI path proxied by means of a selected Picture Content material Supply Community (CDN) area.
If the first methodology fails, the information is delivered on to the attacker’s server. That is outlined within the perform that initializes the outbound community session.
There may be additionally a DNS extraction fallback, the place the information is encrypted and encoded into packets utilizing the Base32 methodology.
Proofpoint attributed the OWAReaper marketing campaign to the TA488 actor primarily based on its behavioral overlap with ZimReaper exercise and the usage of a half-click XSS exploit to focus on webmail viewers for espionage functions.
Researchers printed a small set of indicators of compromise (IoCs), together with the area used and the HTML message physique containing the CVE-2026-42897 exploit and OWAReaper payload.
Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remaining strikes invisibly by means of the surroundings.
Picus’ whitepaper exhibits easy methods to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
