Skip to main content

Tag: ta488

3 articles

Office interior with laptop on a desk, windows and cityscape in background.

Russian Spies Expand Email Attacks to Outlook

Russian spies have set their sights on Microsoft Outlook Web Access, exploiting a cross-site scripting flaw to launch targeted email attacks, just days after being called out for their abuse of a zero-day vulnerability in Zimbra Collaboration Suite. The notorious group, tracked as TA488 or Laundry Bear, has adapted their sneaky half-click technique to compromise on-premises Exchange Servers.

Analyst 207
Rows of computer servers and networking equipment with a focused Microsoft Exchange server interface on a screen.

Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access

Russian hackers have found a sneaky way to keep access to Microsoft mailboxes by exploiting a flaw in Outlook Web Access, making it tough to shake them off even with a full system overhaul. Simply put, these cyber intruders can stick around unless their presence is manually erased from the Exchange server.

Analyst 207
Server room with computer equipment, cables, and rack in a government or corporate office setting.

Russia-Aligned TA488 Exploits Outlook Web Access With Persistent Implant

A Russia-aligned espionage group, known as TA488, has launched a sophisticated attack using a half-click backdoor, exploiting a flaw in Outlook Web Access to deploy a persistent implant. This new implant, dubbed OWAReaper, allows the group to maintain server-side access, marking a significant escalation in their cyber operations.

Analyst 207