Vulnerabilities

CVE-2026-42897 Exploited by Russian Hackers

July 30, 2026 00:00 · 12 min read

Russian hackers, known as Laundry Bear or Void Blizzard, are exploiting a zero-day vulnerability in Exchange Outlook Web Access (OWA) to deliver a sophisticated backdoor called OWAReaper. This vulnerability, tracked as CVE-2026-42897, is a cross-site scripting (XSS) flaw that allows attackers to execute arbitrary JavaScript in the browser context when users open a specially crafted email in the OWA app.

Exploitation and Delivery

The exploitation of this vulnerability was spotted by email security company Proofpoint, which reported that the hackers had been targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors. The attackers leverage the improper HTML sanitization issue in OWA to include malicious code in the messages, adding HTML and JavaScript to the malicious messages.

The exploit delivers a backdoor that researchers call OWAReaper, described as the most sophisticated backdoor delivered via half-click exploits. Analysis revealed a suite of subtle persistence mechanisms, and it is an evolution of the ZimReaper malware observed in attacks against Zimbra email servers.

Persistence Mechanisms

OWAReaper is executed entirely in the Outlook Web Access (OWA) reading pane. Upon execution, it uses Outlook APIs to rewrite the email on the Exchange server and remove the exploit content. Simultaneously, it disables OWA pop-ups and right-click ability while it runs. The malware collects the compromised account’s email address, username, and Outlook settings.

Proofpoint researchers discovered that TA488 (Laundry Bear, Void Blizzard) can maintain access to a target’s mailbox even if their system is restored from a clean image or credentials are rotated. The threat actor achieves this through OWAReaper, which checks for installed Outlook add-ins that have ReadWriteMailbox permissions and uses them to steal OAuth tokens through the GetClientAccessToken operation request.

Command and Control

OWAReaper supports two command-and-control (C2) mechanisms for receiving instructions from the attacker. One of them uses GitHub commit messages as the communication channel. Every 24 hours, the malware queries GitHub's Commit Search API for encrypted messages that match a specific format and include the target's email address.

Laundry Bear also used two methods to exfiltrate data, the main one using HTTPS with AES-CTR encrypted URI paths that would be proxied through certain image content delivery network (CDN) domains. If the primary method fails, the data is delivered directly to the attacker’s server, which is defined in the function that initializes outbound network sessions.

Attribution and Indicators of Compromise

Proofpoint attributed the OWAReaper campaign to the TA488 threat actor based on behavioral overlaps with the ZimReaper activity and the use of half-click XSS exploits to target webmail viewers for espionage purposes. The researchers published a small set of indicators of compromise (IoCs) that includes the domains used and the HTML message body with the CVE-2026-42897 exploit and the OWAReaper payload.

Security teams are advised to test every layer of their security infrastructure to prevent such attacks. The Picus whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free