Russian state-sponsored hackers, identified by the tracking name TA488, are actively exploiting a critical vulnerability in Microsoft's Exchange Server to gain unauthorized access to unpatched computer systems. Security researchers from Proofpoint reported that the group is using this flaw to install advanced malware, steal credentials, and exfiltrate confidential information.
TA488, also known as Laundry Bear and Void Blizzard, has been observed employing similar tactics, including the exploitation of a zero-day vulnerability in Zimbra email services. The group's increased use of 'half-click' exploits, where merely opening an email is sufficient to trigger a compromise, signifies an advancement in their capabilities and tradecraft.
The vulnerability, designated CVE-2026-42897, is a cross-site-scripting (XSS) flaw that Microsoft addressed with mitigation advice in May and a patch in July. It allows for malicious JavaScript execution due to improper filtering of HTML content within emails. Proofpoint suggests TA488 may have exploited this as a zero-day.
Upon exploitation, the malicious JavaScript installs a novel, custom-built browser extension called OWAReaper. This implant is designed to provide attackers with persistent access to victims' Outlook Web Access (OWA) accounts, representing what Proofpoint describes as the most sophisticated backdoor seen delivered via a half-click exploit.