Russian hackers deploy Exchange backdoor that survives password resets

16 sources
  • Proofpoint disclosed that Russia-aligned group TA488 exploited a cross-site scripting flaw in Microsoft Exchange's webmail to target U.S. and European government agencies.
  • The OWAReaper implant executes when victims simply open a crafted email, then grants server-side mailbox access that persists after credential resets and device re-imaging.
  • Campaign infrastructure dates to March, two months before Microsoft disclosed the flaw, suggesting possible zero-day use, according to Proofpoint.
Sources (16)
  1. 1 Russian hackers turn Exchange flaw into 'half-click' mailbox ... www.csoonline.com
  2. 2 RussianTA488 Returns With Persistent Outlook Web ... www.infosecurity-magazine.com
  3. 3 Laundry Bear's new Microsoft Exchange attack triggers on email open (CVE-2026-42897) - Help Net Security www.helpnetsecurity.com
  4. 4 Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation thehackernews.com
  5. 5 TA488 Comes for Outlook with Another Half-Click Exploit www.proofpoint.com
  6. 6 Addressing Exchange Server May 2026 vulnerability CVE- ... techcommunity.microsoft.com
  7. 7 Microsoft Exchange Server flaw actively exploited, no patch ... fieldeffect.com
  8. 8 Alexis Dorais-Joncas' Post www.linkedin.com
  9. 9 Microsoft released a mitigation for Exchange Server www.reddit.com
  10. 10 Released: July 2026 Exchange Server Security Updates x.com
  11. 11 CVE-2026-42897 Detail - NVD nvd.nist.gov
  12. 12 TA488 Targets Zimbra Mailservers with Half-Click Exploits www.proofpoint.com
  13. 13 TA488 Uses Half-Click OWA Exploit to Deploy OWAReaper ... securityonline.info
  14. 14 Russian hackers exploit Exchange OWA zero-day for long- ... www.bleepingcomputer.com
  15. 15 CVE-2026-42897, the Exchange OWA XSS Zero-Day www.penligent.ai
  16. 16 CVE Record: CVE-2026-42897 www.cve.org