top of page

Russian threat group exploits Microsoft OWA vulnerability: The emergence of sophisticated malware OWAReaper

A dangerous cyber attack campaign targeting Microsoft Outlook Web Access (OWA) systems has recently been discovered, directly threatening government agencies in the US and Europe. Furthermore, this wave of attacks has expanded to several other critical sectors, including telecommunications, finance, aerospace, and hospitality. Standing behind this campaign is a Russian-linked threat group using highly stealthy methods to maintain control over victims' mailboxes even after the system undergoes credential changes.

The dangerous "half-click" phishing trap

This campaign began surging on July 22, 2026. This time, hackers exploited the CVE-2026-42897 vulnerability (CVSS severity score: 8.1), a cross-site scripting (XSS) flaw within Microsoft's OWA application. Microsoft had previously warned that this vulnerability was being actively exploited in the wild as early as May 2026.

the-cve-2026-42897-vulnerability
The CVE-2026-42897 vulnerability (CVSS severity score: 8.1) has been actively exploited by hackers

According to cybersecurity firm Proofpoint, the perpetrator behind these attacks is the Laundry Bear group (also known as TA488, CL-STA-1114, UNK_PitStop, and Void Blizzard). This is the same threat group that exploited the zero-day vulnerability CVE-2025-66376 in the classic interface of Zimbra email software starting in July 2025, before it was patched four months later. In previous attack waves, they utilized Proton Mail or compromised accounts to trigger a malware strain named ZimReaper to harvest victims' email data and content within a 90-day window.

In this new campaign targeting Microsoft OWA, the TA488 group has significantly upgraded its technical capabilities. They have shifted to an exploitation method known as "half-click." The alarming aspect of this method is that recipients do not need to click any suspicious links or download attachments; simply opening the email to view it instantly compromises the system.

To achieve this, the actors distribute mass phishing emails with highly generic and mundane topics, such as supply chain analysis, research updates, or travel and natural gas market indicators. Sending such vague content allows them to easily blend into daily spam volumes to evade detection by security systems, while creating a false sense of innocence that prompts unsuspecting users to open and read the emails.

OWAReaper - A weapon hiding in the web browser

When a malicious email is opened, hidden JavaScript code embedded within the social media icons (HTML format) in the email body automatically triggers. This process downloads a previously undocumented browser-based malware implant codenamed OWAReaper.

Researchers assess OWAReaper as the most sophisticated spyware ever distributed via a "half-click" mechanism, essentially representing a profound evolution from the earlier ZimReaper malware. Operating directly within the OWA reading pane, OWAReaper executes the following sophisticated actions:

  • Utilizes Outlook APIs to log emails on the Exchange server, then automatically wipes the exploit-containing content to erase its tracks.

  • Disables pop-up windows and blocks right-click functionality for the user during execution to prevent suspicion.

  • Generates a unique session key for each target, collecting information regarding the victim's email address, username, and Outlook settings.

  • Secretly injects hidden input fields into the web page structure (DOM) to leverage the browser's autofill feature and steal the user's saved OWA passwords.

  • Writes an encrypted copy of itself along with a decryption tool into the browser's local storage (localStorage), allowing the malware to relaunch whenever the user opens a new OWA tab.

Persistence capabilities that challenge security experts

The pinnacle of OWAReaper's threat lies in how it establishes persistent, long-term access. The malware scans Outlook extensions to check if they have read/write permissions for the mailbox. If they do, it hijacks the authentication tokens (OAuth tokens) and grants supreme "Owner" privileges to the Default user account across all mail folders. This means any authenticated account within the same organization can view the entire compromised mailbox.

Because these permissions are altered directly on the Exchange server side, standard incident response and remediation measures are entirely futile. Even if the victim changes their password or completely wipes and reinstalls the device's operating system, the threat actors remain un-evicted. The only way to completely eradicate it is for administrators to log into the Exchange server and manually remove these malicious permissions.

Furthermore, OWAReaper prepares an alternative fallback plan: injecting a hidden frame into OWA's offline IndexedDB cache. When the caching feature is enabled, simply reopening the old malicious email from this cache will instantly re-infect the device, even if the computer's operating system has just been reinstalled.

Sophisticated command control and data exfiltration

To receive commands from its operators, OWAReaper employs two parallel communication channels: via the GitHub platform or directly through incoming emails.

For the GitHub channel, every 24 hours, the malware automatically queries GitHub's search API to scan for update notifications containing the target's email address. Once found, the command data is decrypted using a hardcoded key and a session-specific AES key to prevent third-party interception. The malware parses prefix characters to execute three core commands: code (replace the entire OWAReaper source code), domn (change the C&C command server), and cmnd (execute arbitrary JavaScript snippets). As for the email channel, it continuously scans the IndexedDB storage for messages matching a predefined structure that contains the target email along with a Base64-encrypted text block to execute identical commands.

Once data is harvested, OWAReaper prioritizes exfiltrating it via the secure HTTPS protocol using encrypted paths. In the event that this method is blocked, the malware shifts to a DNS label tunneling technique - disguising the data within standard Domain Name System queries - to covertly exfiltrate information to an attacker-controlled domain.

Analysis reveals that the infrastructure supporting this campaign was established as early as March 2026, two months before the CVE-2026-42897 vulnerability was publicly disclosed by Microsoft. This implies that the campaign could have been deployed as a zero-day exploit beforehand. Although the Laundry Bear group is intentionally broadening its target scope across various economic sectors to blend into standard spam traffic and evade security investigations, their core objective remains unchanged: persistently gathering intelligence against government agencies and the defense sector.

Proactive defense solutions against sophisticated threats with IPSIP Vietnam

In the face of stealthy malware and covert "half-click" attack tactics like OWAReaper, relying solely on antivirus software is entirely insufficient. As evasive malware attacks grow increasingly complex, enterprises require a more proactive and comprehensive defense strategy to safeguard their core systems.

IPSIP Vietnam provides an ecosystem of international-standard cybersecurity solutions and IT infrastructure, helping protect enterprise data assets from within. To counter dangerous malware, businesses can equip themselves with defense-in-depth layers from IPSIP:

  • NDR (Network Detection and Response) service: A solution that deploys artificial intelligence technology to trace and detect the most advanced threats directly at the network layer. It analyzes anomalous behavior to rapidly isolate attacks hiding deep within the system.

  • 24/7 Cybersecurity Monitoring Center (SOC): Continuous network monitoring to detect threats in a timely manner and rapidly respond to incidents, protecting data assets before the system faces risks of disruption.

  • Hands-on expert team: IPSIP's experts hold world-class technology certifications (such as Fortinet, SentinelOne, Sekoia, Wallix, Eset...), ensuring timely incident response across all highly complex infrastructure environments.

ipsip-viet-nam
IPSIP Vietnam provides an international-standard cybersecurity solution ecosystem, optimizing enterprise IT infrastructure

Protect your cyberspace today!

Don't wait until your system becomes the next target for hackers. Proactively protect your business's digital assets by scheduling a free consultation with a cybersecurity expert at IPSIP Vietnam.


Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page