Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

csoonline+1helpnetsecurity+1csoonline+1A Russia-aligned cyber espionage group known as Laundry Bear has been exploiting a vulnerability in Microsoft Exchange's webmail interface to compromise government agencies and private sector organizations across the United States and Europe, deploying a browser-based backdoor that can survive credential changes and full device re-imaging.
The campaign, which began on July 22, was disclosed on July 29 by enterprise security firm Proofpoint. The group, also tracked as TA488 and Void Blizzard, weaponized CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access that allows malicious JavaScript to execute when a victim simply opens a crafted email — no link clicks or attachments required.csoonline+2
Targets included U.S. and European government entities as well as organizations in the telecommunications, financial, hospitality, and aerospace sectors. The emails used deliberately bland subject lines mimicking routine informational updates on topics like supply chains and market indicators, designed so recipients would open them, skim, and dismiss them as junk without reporting.helpnetsecurity+2
The exploit delivers OWAReaper, a previously undocumented JavaScript implant that Proofpoint called the most sophisticated half-click backdoor it has observed. Running entirely within OWA's reading pane with no conventional file on disk, OWAReaper rewrites the original email on the server to erase evidence of compromise, harvests credentials via browser autofill, and stores an encrypted copy of itself in browser localStorage so it re-executes each time a new OWA tab opens.thehackernews+2
Its most durable technique is server-side: the malware exploits Outlook add-ins with ReadWriteMailbox permissions to steal OAuth tokens and grant Owner-level access to Exchange's built-in "Default" user on every mail folder. This means any authenticated account in the same organization can access the victim's mailbox indefinitely. "Credential rotation and even full re-imaging of the targeted user's device will not evict the actor," Proofpoint warned.infosecurity-magazine+1
Microsoft first disclosed CVE-2026-42897 on May 14, 2026, issuing an emergency mitigation before releasing a permanent fix in June. However, Proofpoint found that campaign infrastructure was created in March 2026, making it feasible the group exploited the flaw as a zero-day.techcommunity.microsoft+3
Organizations are urged to install Microsoft's security updates and, if potentially compromised, undertake a multi-step cleanup including revoking Exchange Web Services tokens, removing Default-user folder permissions, and clearing OWA's offline database and localStorage.infosecurity-magazine+1