Russian hackers exploit Exchange OWA zero-day for persistent access

Russian state-sponsored hackers exploit a zero-day vulnerability in Microsoft Exchange Outlook Web Access to deploy the OWAReaper backdoor.

By Central
This campaign, detected by Proofpoint, targets government and private sector entities using a novel half-click exploit.
Highlights
  • The Laundry Bear group exploited CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange OWA.
  • The attack deploys a backdoor called OWAReaper, which persists by modifying Exchange mailbox folder permissions.
  • Proofpoint discovered the campaign and urges organizations to apply Microsoft's security updates for CVE-2026-42897.

The Russian state-sponsored hacking group tracked as Laundry Bear, also known as Void Blizzard and TA488, has been actively exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access to deploy a sophisticated new backdoor called OWAReaper. This campaign, detected by email security firm Proofpoint, represents a significant escalation in the group’s tradecraft, targeting government entities in the United States and Europe, alongside organizations in the telecommunications, financial, hospitality, and aerospace sectors. The attacks leverage CVE-2026-42897, a cross-site scripting vulnerability in OWA that allows the execution of arbitrary JavaScript simply by opening a specially crafted email.

The Mechanics of a “Half-Click” Zero-Day Exploit

The Laundry Bear operation exploits a critical flaw in how Microsoft Exchange sanitizes HTML content within email messages. Specifically, the vulnerability identified as CVE-2026-42897 permits the server to improperly process HTML code, enabling a threat actor to inject and execute JavaScript within the browser context of the recipient’s OWA session. Researchers at Proofpoint have designated this technique a “half-click exploit” because no user interaction beyond opening the malicious email is required to trigger the attack.

Microsoft issued an advisory for CVE-2026-42897 on May 14, confirming that the flaw was already being exploited as a zero-day in active attacks. Proofpoint’s investigation indicates that Laundry Bear had established its attack infrastructure for this campaign as early as March, nearly two months before the advisory was published. This timeline reveals a deliberate and well-prepared offensive operation that capitalized on an unpatched vulnerability.

The threat actor employed highly tailored lures to entice victims. Subject lines and email bodies focused on topics likely to interest specific targets, including supply-chain analysis, research updates, and performance indicators for the tourism and natural gas markets. Proofpoint notes that these messages were deliberately “banal,” designed to be skimmed and dismissed as routine correspondence, thereby reducing the likelihood that the recipient would report it as suspicious. Critically, the emails contained no conventional malicious attachments or URLs, making them exceptionally difficult to detect through standard email security gateways.

Understanding CVE-2026-42897: The OWA Flaw

For those asking, “What exactly is CVE-2026-42897?” it is a cross-site scripting vulnerability present in the Outlook Web Access module of Microsoft Exchange Server. The root cause lies in improper HTML sanitization. When Exchange processes a message body, it fails to neutralize malicious code embedded in specific HTML elements. An attacker can craft an email containing obfuscated JavaScript that bypasses the server’s filters. Once the email is rendered in the victim’s browser, the injected script executes with the same permissions as the authenticated OWA session, granting the attacker a foothold inside the user’s mailbox environment.

OWAReaper: A New Generation of Persistent Email Malware

The payload delivered via this exploit is a backdoor that Proofpoint researchers have named OWAReaper, describing it as the most sophisticated malware they have observed from a half-click campaign. OWAReaper is an evolution of the ZimReaper malware, which the same group previously used to exploit a zero-day vulnerability in Zimbra email servers. Unlike traditional malware that operates at the operating system level, OWAReaper executes entirely within the OWA reading pane of the victim’s browser.

Stealth and Self-Preservation Tactics

Upon execution, OWAReaper demonstrates advanced operational security. It immediately uses Outlook APIs to rewrite the email on the Exchange server, effectively removing its own exploit code from the server-side message. This action erases the forensic trail of the initial infection vector. Simultaneously, the malware disables OWA’s pop-up notifications and right-click functionality while it runs, preventing the user from accidentally interfering with its operations or noticing any unusual browser behavior.

The malware performs extensive reconnaissance of the compromised account. It collects the mailbox’s email address, username, and Outlook settings. A particularly aggressive data theft technique involves creating invisible elements within the browser’s Document Object Model (DOM). These elements are designed to capture credentials when the browser’s password manager automatically fills in stored login forms, thereby stealing the user’s access credentials silently.

How OWAReaper Achieves Persistent Access

A common question security professionals are asking is, “How does OWAReaper maintain persistent access to a mailbox?” The answer lies in two distinct and highly effective persistence mechanisms that are both server-side and client-side, making them exceptionally resistant to standard remediation.

Persistence via Exchange Server Permissions

The first mechanism exploits the way Microsoft Exchange handles mailbox permissions. OWAReaper checks for any installed Outlook add-ins that possess ReadWriteMailbox permissions. It then leverages these add-ins to execute a GetClientAccessTokencodecodecodecode operation request, stealing OAuth tokens associated with the account. Using these tokens, the malware calls the UpdateFoldercodecodecodecode API to grant itself “Owner”-level permissions to the ‘Default’ user—a low-privilege preset alias found in all Microsoft Exchange tenants—on every mail folder within the compromised mailbox.

Because mailbox permissions are configured on the Exchange server side, this persistence method is remarkably resilient. Even if the compromised user’s password is changed, or their entire workstation is restored from a clean image, the attacker retains full access to the mailbox. Any authenticated account within the same organization can be used to access the compromised mailbox due to these manipulated permissions.

Persistence via Offline Browser Cache

The second persistence mechanism targets the client-side storage of the OWA application. OWAReaper enables caching within the browser and then injects a malicious iframe into the HTML of emails stored in OWA’s offline IndexedDB database. This iframe executes every time the victim opens a cached, poisoned email. Even if the user is offline, the malicious code runs, ensuring continuous access and data exfiltration capability.

Dual Communication and Exfiltration Channels

To ensure resilient command-and-control communications and data theft, the malware implements a dual-track architecture for both receiving instructions and sending stolen information.

For command-and-control, OWAReaper supports two channels. The primary method involves querying GitHub’s Commit Search API every 24 hours. The malware searches for commit messages that match a specific encrypted format and contain the target’s email address. The secondary C2 channel parses emails delivered directly to the target’s mailbox. It scans the IndexedDB for message bodies that match the format {target_email_address}{space}{Base64text}codecodecodecode, decoding instructions from seemingly innocuous incoming mail.

Data exfiltration is similarly redundant. The primary method uses HTTPS with AES-CTR encrypted URI paths, proxied through trusted image content delivery network domains. If this channel fails, the malware falls back to sending data directly to an attacker-controlled server. A tertiary DNS exfiltration method exists, where data is encrypted and encoded in Base32 before being sent over DNS queries.

Historical Context: From Zimbra to Exchange

This campaign is not an isolated event but part of a broader pattern of espionage activity by Laundry Bear. The group previously exploited CVE-2025-66376, another cross-site scripting zero-day, albeit in Zimbra email servers. That campaign delivered the ZimReaper malware, which targeted the theft of email communications, two-factor authentication codes, application passcodes, and passwords. The current operation against Exchange servers represents a natural and dangerous evolution of the group’s capabilities, shifting from one widely used enterprise email platform to another, applying the same core tradecraft while significantly enhancing the sophistication of the payload.

Indicators of Compromise and Recommendations

Proofpoint has released a set of indicators of compromise for this campaign. Organizations are urged to review their Exchange server logs for any exploitation attempts related to CVE-2026-42897. Specific attention should be paid to unusual HTML or JavaScript content within email bodies, especially those that appear benign but contain Base64-encoded payload blobs embedded after the ‘#’ character in social media icon URLs.

Additionally, security teams should audit Exchange mailbox permissions for any mail folders where the ‘Default’ user has been granted Owner-level permissions unexpectedly. Monitoring for anomalous GetClientAccessTokencodecodecodecode or UpdateFoldercodecodecodecode API calls originating from OWA sessions is also critical. Proactive application of Microsoft’s security updates for CVE-2026-42897 remains the most effective defense against initial exploitation.

The emergence of OWAReaper underscores a fundamental shift in how advanced persistent threat groups are targeting enterprise collaboration tools. By operating entirely within the browser context of a legitimate application, leveraging server-side persistence unrelated to user credentials, and utilizing dual, resilient communication channels, this malware represents a formidable challenge for traditional security architectures. Organizations must now consider that endpoint hygiene and credential rotation are insufficient defenses against a threat that can burrow into the very permissions model of their email platform. The only reliable defense is a combination of rigorous vulnerability management, continuous monitoring for anomalous server-side behavior, and a deep understanding of the attack surface presented by webmail interfaces.

Share This Article