Tag: ta488
3 articles

Russian Spies Expand Email Attacks to Outlook
Russian spies have set their sights on Microsoft Outlook Web Access, exploiting a cross-site scripting flaw to launch targeted email attacks, just days after being called out for their abuse of a zero-day vulnerability in Zimbra Collaboration Suite. The notorious group, tracked as TA488 or Laundry Bear, has adapted their sneaky half-click technique to compromise on-premises Exchange Servers.

Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access
Russian hackers have found a sneaky way to keep access to Microsoft mailboxes by exploiting a flaw in Outlook Web Access, making it tough to shake them off even with a full system overhaul. Simply put, these cyber intruders can stick around unless their presence is manually erased from the Exchange server.

Russia-Aligned TA488 Exploits Outlook Web Access With Persistent Implant
A Russia-aligned espionage group, known as TA488, has launched a sophisticated attack using a half-click backdoor, exploiting a flaw in Outlook Web Access to deploy a persistent implant. This new implant, dubbed OWAReaper, allows the group to maintain server-side access, marking a significant escalation in their cyber operations.