Skip to main content
Emerging ThreatsMalware & Ransomware

Russian Spies Expand Email Attacks to Outlook

Office interior with laptop on a desk, windows and cityscape in background.

TA488 began exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA), a day before researchers and government agencies exposed the group's abuse of a zero‑day in Zimbra Collaboration Suite.

TA488's move from Zimbra to Outlook Web Access

Proofpoint says the Russian espionage crew it tracks as TA488, or "Laundry Bear," has adapted a previously reported "half‑click" technique used against Zimbra and is now targeting Microsoft Outlook Web Access on on‑premises Exchange Server with CVE-2026-42897. According to the vendor, the activity was observed as part of a broader espionage campaign rather than isolated exploitation, and began against OWA at nearly the same time researchers were publicly discussing the Zimbra attacks.

How the half‑click attack executes inside a mail session

Unlike conventional phishing that depends on convincing a user to follow a link or download a file, this attack requires only that a target open the booby‑trapped message inside OWA. Proofpoint described the mechanism: if a target opens the crafted message in OWA, the browser executes attacker‑controlled JavaScript inside the victim's authenticated mail session. Exchange Online is not affected, the researchers emphasized.

OWAReaper: a mailbox‑resident implant that leaves few traces

Instead of installing conventional endpoint malware, the adversary deploys a browser implant Proofpoint calls OWAReaper. The implant "lives entirely inside OWA," meaning the foothold is in the compromised mailbox rather than on the Windows host. Proofpoint said OWAReaper leaves virtually no host artifacts, communicates over two command‑and‑control channels, supports multiple methods of exfiltrating data, and can survive browser restarts, password changes, and even a complete device rebuild because the persistence is mailbox‑level.

Targets and campaign scope: hiding in plain sight

Proofpoint reported TA488 used the OWA flaw to target government organizations in the US and Europe along with telecommunications, financial services, hospitality, and aerospace companies. The researchers suggested the campaign's unusually broad scope may have been deliberate: "TA488 appears to demonstrate interest in a wide range of sectors while maintaining priorities for intelligence collection against government and defense," they wrote. Proofpoint added that the group's lure themes are intentionally nondescript: "Lure themes remain generic and unremarkable, so the target is more inclined to open and skim the email but ultimately overlook it."

What this means for government organizations, telecommunications providers, and affected enterprises

  • Government organizations: Proofpoint indicated TA488 maintains collection priorities focused on government and defense. Those organizations will need to consider that successful exploitation can grant an attacker persistent access to mailboxes even if individual endpoints are rebuilt or passwords are changed.
  • Telecommunications providers: Listed as a target in Proofpoint's findings, telecommunications firms should note the campaign's mix of broad targeting and mailbox persistence, which could allow attackers to blend activity into routine email traffic.
  • Financial services, hospitality, and aerospace companies: All named as targets, these enterprises should be aware that the implant resides in OWA mailboxes and leaves "virtually no host artifacts," complicating traditional host‑based detection and response.

Proofpoint also believes TA488 may have been exploiting the OWA flaw as a zero‑day: the vendor cited attacker infrastructure dating back to March, roughly two months before Microsoft's out‑of‑band patch in May. Microsoft "did not immediately respond to The Register's questions," the reporting noted. If Proofpoint's timeline is correct, TA488's activity would predate public awareness of the vulnerability and signal the group has refined a technique that sidesteps a core piece of conventional security advice — "don't click suspicious links." Proofpoint summed up the tactical shift: "If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488."

The published record leaves a concrete ledger of what defenders must reconcile: an implant that lives in mailboxes, a vulnerability that has been patched by Microsoft for on‑premises Exchange Server, and evidence suggesting the adversary may have had months of operational infrastructure in place before disclosure. The crucial unanswered question, based on Proofpoint's assessment, is how long that mailbox‑level access went undetected while the attackers refined both exploit and implant.

Original story at The Register