A Russian espionage group tracked as TA488 has expanded beyond Zimbra, weaponizing a cross-site scripting vulnerability in Microsoft Outlook Web Access (OWA) to implant browser-based backdoors that survive password changes and complete device rebuilds.
Proofpoint researchers found that the group, also known as Laundry Bear, exploited CVE-2026-42897 starting July 22, a day before authorities disclosed the same crew was abusing a Zimbra zero-day. The OWA flaw, which Microsoft patched in May, allows attacker-controlled JavaScript to execute inside a victim’s authenticated mail session when they simply open a crafted message. No link clicking or file downloading is required, making it a half-click attack that bypasses traditional phishing defenses.
Exchange Online users are not affected, but on-premises Exchange Server 2016 and 2019 installations are vulnerable. Proofpoint identified infrastructure tied to the campaign dating back to March, suggesting TA488 may have exploited the flaw as a zero-day before Microsoft’s disclosure.
The implant, dubbed OWAReaper, lives entirely inside the browser and leaves almost no host artifacts. It communicates over two command-and-control channels, supports multiple exfiltration methods, and can grant OAuth-level access to Exchange mail folders. Because the backdoor resides in the compromised mailbox rather than on the endpoint, changing the victim’s password or rebuilding the device does not remove it.
Targets included government agencies in the US and Europe, as well as telecommunications, financial, hospitality, and aerospace companies. The attackers used intentionally vague email lures resembling routine business updates to avoid raising suspicion.
