All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Kremlin hackers exploit Exchange flaw for network backdoors

Created at 30 Jul · 9:06 PM1 source↑ Market-relevant
IN SHORT

Russian state-backed hackers, identified as TA488, are leveraging a critical vulnerability in Microsoft Exchange Server to gain unauthorized access to unpatched networks. The attackers use a 'half-click' exploit, where opening a malicious email triggers the compromise, installing advanced malware and stealing sensitive information.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

CVE-2026-42897vulnerability identifier

Who's Involved

TA488
Kremlin-backed hacking group exploiting Exchange Server vulnerability
Proofpoint
Security researchers detailing the TA488 attacks
Microsoft
Vendor of the exploited Exchange Server software
National Security Agency
Jointly warned about TA488's activities
Kremlin hackers exploit Exchange flaw for network backdoors

↳ Why This Matters

The exploitation of a critical vulnerability in Microsoft Exchange Server by state-sponsored hackers poses a significant risk to organizations worldwide, potentially leading to widespread data breaches and network compromises.

Key facts

  • Russian state hackers (TA488) are exploiting a critical Microsoft Exchange Server vulnerability.
  • The exploit allows attackers to backdoor unpatched networks and steal credentials.
  • Compromise occurs when a user opens a specially crafted email in Outlook Web Access (OWA).
  • The vulnerability, CVE-2026-42897, is a cross-site-scripting (XSS) flaw.
  • A new implant named OWAReaper provides persistent access to victim accounts.

Russian state-sponsored hackers, identified by the tracking name TA488, are actively exploiting a critical vulnerability in Microsoft's Exchange Server to gain unauthorized access to unpatched computer systems. Security researchers from Proofpoint reported that the group is using this flaw to install advanced malware, steal credentials, and exfiltrate confidential information.

TA488, also known as Laundry Bear and Void Blizzard, has been observed employing similar tactics, including the exploitation of a zero-day vulnerability in Zimbra email services. The group's increased use of 'half-click' exploits, where merely opening an email is sufficient to trigger a compromise, signifies an advancement in their capabilities and tradecraft.

The vulnerability, designated CVE-2026-42897, is a cross-site-scripting (XSS) flaw that Microsoft addressed with mitigation advice in May and a patch in July. It allows for malicious JavaScript execution due to improper filtering of HTML content within emails. Proofpoint suggests TA488 may have exploited this as a zero-day.

Upon exploitation, the malicious JavaScript installs a novel, custom-built browser extension called OWAReaper. This implant is designed to provide attackers with persistent access to victims' Outlook Web Access (OWA) accounts, representing what Proofpoint describes as the most sophisticated backdoor seen delivered via a half-click exploit.

Frequently asked questions

TA488 is the designation for a Russian state-backed hacking group that is actively exploiting vulnerabilities in email services.

CVE-2026-42897 is a cross-site-scripting (XSS) vulnerability in Microsoft Exchange Server that allows for malicious JavaScript execution.

OWAReaper is a novel, custom-built JavaScript browser extension used by TA488 to gain persistent access to victim OWA accounts.

A 'half-click' exploit is a type of cyberattack where the mere act of opening an email or viewing a webpage is enough to trigger a compromise, without requiring further user interaction.

What Happens Next

01Organizations are urged to apply Microsoft's July security patches for Exchange Server.
02Users should be vigilant about opening emails from unknown or suspicious sources.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Russian state hackers are exploiting a critical vulnerability in Microsoft Exchange Server.
The attacks are attributed to TA488, a group working for the Kremlin.
TA488 previously exploited a zero-day vulnerability in Zimbra email service.
The Exchange Server vulnerability allows for malware installation and credential theft upon opening an email.
Researchers noted improved loading mechanisms, techniques, and malware used by TA488.
A new JavaScript browser-based implant, OWAReaper, is used for persistent access.
The vulnerability, CVE-2026-42897, is a cross-site-scripting (XSS) flaw patched by Microsoft in July.
TA488 may have exploited the vulnerability as a zero-day.

Sources

T1
Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networksvar abtest_2165536 = new ABTest(2165536, 'impression');Ars Technica

Related Stories

Chrome may get faster updates with no restart required
30 Jul · 7:31 PM
Model Context Protocol updates target enterprise scale with stateless design
30 Jul · 2:56 PM
Google AI helps fix record number of Chrome security bugs
30 Jul · 7:31 PM
Space Force mission demonstrates satellite 'dogfighting' in orbit
30 Jul · 5:41 PM
Physical game discs increasingly require downloads, study finds
30 Jul · 8:16 PM