The Russian state-sponsored hacking group Laundry Bear, often known as Void Blizzard, is exploiting an Alternate Outlook Net Entry vulnerability in electronic mail campaigns to ship a classy backdoor known as OWAReaper.
E-mail safety firm Proofpoint noticed the exercise per week in the past concentrating on varied organizations, together with authorities entities within the U.S. and Europe, and firms within the telecommunications, monetary, hospitality, and aerospace sectors.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that permits executing arbitrary JavaScript within the browser context when customers open a specifically crafted electronic mail within the Outlook Net Entry (OWA) app.
Beforehand, the identical hackers leveraged one other XSS vulnerability (CVE-2025-66376) as a zero-day in Zimbra electronic mail servers to ship malware ZimReaper that steals electronic mail communication, two-factor authentication (2FA) codes, software passcodes, and passwords.
Proofpoint researchers discuss with this type of XSS exercise on webmail platforms as a “half-click exploit” as a result of customers solely must open the malicious electronic mail to set off the exploited vulnerability.
Improper HTML sanitization
In a brand new report right this moment, Proofpoint describes Laundry Bear’s new half-click exploit marketing campaign as a major “enchancment within the group’s tradecraft and functionality.”
Based mostly on Microsoft’s advisory on Could 14 for the CVE-2026-42897 flaw in OWA, the menace actor was already exploiting it as a zero-day.
The safety problem causes the server to improperly sanitize the HTML code within the message physique, which might be leveraged to run JavaScript when opening the e-mail.
In keeping with Proofpoint, Laundry Bear, which the corporate tracks as TA488, had created the assault infrastructure for the OWAReaper marketing campaign in March, nearly two months earlier than Microsoft’s warning.
Within the newest noticed exercise, the menace actor used messages on matters of curiosity to the goal, reminiscent of supply-chain analyses, analysis updates, and efficiency indicators for tourism and gasoline markets.
“The topic traces and lures are banal, probably so the focused consumer opens and skims the message, however dismisses the message as junk with out reporting it, particularly on condition that there aren’t any suspicious URLs or attachments current.”
Proofpoint explains that the attacker leverages the improper sanitization problem to incorporate malicious code within the messages so as to add HTML and JavaScript within the malicious messages.
Emails contained a JavaScript loader and Base64-encoded payload blobs embedded in social media icon URLs after the ‘#’ character.

supply: Proofpoint
The exploit delivers a backdoor that researchers name OWAReaper and describe as “probably the most subtle backdoor delivered by way of half-click exploits” they noticed.
Evaluation revealed a “suite of refined persistence mechanisms” and revealed it to be an evolution of the ZimReaper malware noticed within the assaults towards Zimbra electronic mail servers.
“OWAReaper is executed fully within the Outlook Net Entry (OWA) studying pane. Upon execution, it makes use of Outlook APIs to rewrite the e-mail on the Alternate server and take away the exploit content material. Concurrently, it disables OWA pop-ups and right-click capacity whereas it runs,” Proofpoint says.
The malware collects the compromised account’s electronic mail handle, username, and Outlook settings. It additionally tries to steal the entry credentials by creating invisible components within the Doc Object Mannequin (DOM) and ready for the browser to routinely fill them in.
Lengthy-term persistence mechanism
Proofpoint researchers found that TA488 (Laundry Bear, Void Blizzard) can preserve entry to a goal’s mailbox even when their system is restored from a clear picture or credentials are rotated.
The menace actor achieves this by way of OWAReaper, which checks for put in Outlook add-ins which have ReadWriteMailbox permissions and makes use of them to steal OAuth tokens by way of the GetClientAccessToken operation request.
“It then calls UpdateFolder to grant itself Proprietor-level permissions to the ‘Default’ consumer (a low-permission preset alias in all Microsoft Alternate tenants) on each mail folder,” the researchers clarify.
This permits attackers to entry the mailbox from any authenticated account throughout the group.
As a result of mailbox permissions are configured on the server facet, altering the compromised consumer’s credentials or reinstalling the affected system doesn’t revoke the attackers’ entry.
OWAReaper implements a second persistence mechanism by enabling caching and injecting a malicious iframe within the HTML of messages saved in OWA’s offline IndexedDB.
“This iframe executes each time the sufferer opens a poisoned electronic mail from the cache,” the researchers say.
Two of every little thing
The malware helps two command-and-control (C2) mechanisms for receiving directions from the attacker. One in every of them makes use of GitHub commit messages because the communication channel.
Each 24 hours, the malware queries GitHub’s Commit Search API for encrypted messages that match a selected format and embrace the goal’s electronic mail handle.
OWAReaper also can parse emails delivered to the goal’s mailbox. It checks the IndexedDB for message our bodies with the {target_email_address}{house}{Base64text} construction.
Laundry Bear additionally used two strategies to exfiltrate knowledge, the primary one utilizing HTTPS with AES-CTR encrypted URI paths that will be proxied by way of sure picture content material supply community (CDN) domains.
If the first methodology fails, the information is delivered on to the attacker’s server, which is outlined within the operate that initializes outbound community classes.
There may be additionally a DNS exfiltration fallback, the place knowledge is encrypted, then encoded in packets utilizing the Base32 methodology.
Proofpoint attributed the OWAReaper marketing campaign to the TA488 menace actor primarily based on behavioral overlaps with the ZimReaper exercise and using half-click XSS exploits to focus on webmail viewers for espionage functions.
The researchers revealed a small set of indicators of compromise (IoCs) that features the domains used and the HTML message physique with the CVE-2026-42897 exploit and the OWAReaper payload.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remaining transfer by way of your surroundings unseen.
The Picus whitepaper exhibits how breach and assault simulation checks your SIEM and EDR guidelines so threats cease slipping by detection.


