← Back to Feed

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

CVE-2026-42897

July 29, 2026 · BleepingComputer · Severity: CRITICAL

Russian state-sponsored hacking group Laundry Bear (Void Blizzard / TA488) is actively exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange Outlook Web Access (OWA), to deliver a sophisticated backdoor called OWAReaper. Proofpoint discovered the campaign targeting U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors. The vulnerability is a 'half-click exploit' — simply opening a specially crafted email triggers the XSS without any user interaction beyond viewing the message. OWAReaper is the most advanced backdoor delivered via half-click exploits, featuring multiple persistence mechanisms including granting Owner-level mailbox permissions to the 'Default' user (which persists across credential rotation and system reimages) and injecting malicious iframes into OWA's offline IndexedDB cache. The malware uses dual command-and-control channels, including GitHub commit messages and email parsing, with HTTPS and DNS-based data exfiltration.

Key Takeaways

  • Half-click exploit requires no user action — Opening a malicious email in OWA is enough to trigger the XSS vulnerability — no clicking links or attachments needed.
  • Server-side persistence survives credential changes — OWAReaper grants Owner-level permissions on all mail folders to the 'Default' user, so rotating passwords or reimaging the endpoint does not revoke access.
  • Dual C2 via GitHub and email — The malware uses GitHub Commit Search API and parsed email messages as command channels, making detection more difficult.
☕ Buy a Coffee