Eilmeldung
FRLa Fifa abandonne son projet de structure commerciale avec des investisseurs privésFRIncendie dans le Var : 1 000 hectares supplémentaires brûlés et 2 500 personnes évacuéesFRLe ministre des Transports Philippe Tabarot redoute des départs de feu sur les routesFRTotalEnergies finance le carburant des pompiers et l'A400M est déployé contre les incendies en GirondeFRAfflux massif de migrants à Ceuta : causes et tensions diplomatiquesFRGoogle Earth : la nouvelle fonctionnalité d’IA qui inquiète les spécialistes de la désinformationFRLe château de Miraval, ex-propriété de Brad Pitt et Angelina Jolie, menacé par les incendies dans le VarFRIncendie en Gironde : le brasier de Saumos "stabilisé" après avoir ravagé 42 000 hectaresFRBonne fréquentation des cinémas en France cet été 2026FROpenAI franchit le milliard d'utilisateurs et ajuste sa politique tarifaireFRLa Fifa abandonne son projet de structure commerciale avec des investisseurs privésFRIncendie dans le Var : 1 000 hectares supplémentaires brûlés et 2 500 personnes évacuéesFRLe ministre des Transports Philippe Tabarot redoute des départs de feu sur les routesFRTotalEnergies finance le carburant des pompiers et l'A400M est déployé contre les incendies en GirondeFRAfflux massif de migrants à Ceuta : causes et tensions diplomatiquesFRGoogle Earth : la nouvelle fonctionnalité d’IA qui inquiète les spécialistes de la désinformationFRLe château de Miraval, ex-propriété de Brad Pitt et Angelina Jolie, menacé par les incendies dans le VarFRIncendie en Gironde : le brasier de Saumos "stabilisé" après avoir ravagé 42 000 hectaresFRBonne fréquentation des cinémas en France cet été 2026FROpenAI franchit le milliard d'utilisateurs et ajuste sa politique tarifaire
Newsgather
ZurückRussian State Hackers Exploit Microsoft Outlook Vulnerability with OWAReaper Malware
Russian State Hackers Exploit Microsoft Outlook Vulnerability with OWAReaper Malware
Dringend
Ars Technicavor 5 StundenDefense3 Min. LesezeitUnited States

Russian State Hackers Exploit Microsoft Outlook Vulnerability with OWAReaper Malware

Auf einen Blick

Russian state-sponsored group TA488 is exploiting a maximum-severity Microsoft Outlook Exchange Server vulnerability (CVE-2026-42897) to install sophisticated OWAReaper malware, stealing credentials and gaining persistent access to OWA accounts.

KI-generierte Zusammenfassung

Warum es wichtig ist

TA488, also known as Laundry Bear and Void Blizzard, previously exploited a zero-day vulnerability in Zimbra's email service. This new campaign shows improved tradecraft.

Schriftgröße

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday.

The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email service from Zimbra. The revelation that TA488 is also exploiting the Exchange Server vulnerability to install advanced malware when a user does nothing other than open an email sent to an Outlook Web Access (OWA) account has elevated the group’s profile and assessments of its abilities.

“TA488 is doubling down on the use of ‘half-click’ exploits—where opening the email is enough to trigger compromise—with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability,” Proofpoint researchers wrote. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.”

The vulnerability, tracked as CVE-2026-42897, is a cross-site-scripting vulnerability, usually abbreviated as XSS, that Microsoft provided mitigation advice for in May and patched in July. Microsoft gave it a maximum severity rating. The vulnerability, which stems from a failure to properly filter HTML embedded in an email, allows malicious JavaScript execution. Proofpoint said that TA488 may have exploited it as a zero-day.

The malicious JavaScript installs a novel, custom-built browser extension that gives attackers persistent access to victims’ OWA accounts. Proofpoint said it was the most sophisticated backdoor the company has ever seen delivered through a half-click exploit. The company has named it OWAReaper.

Company researchers explained:

OWAReaper is executed entirely in the Outlook Web Access (OWA) reading pane. Upon execution, it uses Outlook APIs to rewrite the email on the Exchange server and remove the exploit content. Simultaneously, it disables OWA pop-ups and right-click ability while it runs. OWAReaper then creates a session key, unique to each target, and begins gathering the target’s email address, username and Outlook settings. It then creates two invisible input elements in the DOM and waits for the browser’s autofill to enter the username and password to gather the user’s OWA saved credentials.

OWAReaper then writes an encrypted version of itself, and a decryption wrapper, into the browser’s localStorage, under settings fields in the PageDataPayload.OwaUserDefaultSettings key. This is a legitimate key used by OWA in its page rendering, where OWA evaluates OwaFrontendSyncState itself as part of its own sync restore flow. Every time the user opens an OWA tab in the browser, the normal OWA sync process automatically executes OWAReaper.

In many cases, the backdoor can go on to steal OAuth tokens and, from there, gain full access to the mailbox of any authenticated user on the same network. “This persistent access lives on the server side and requires deliberate removal from the Exchange server; credential rotation and even full re-imaging of the targeted user’s device will not evict the actor,” Proofpoint said.

It’s not clear if machines compromised by OWAReaper are disinfected once Microsoft’s July patch or a separate Exchange Emergency Mitigation service is installed. Proofpoint is advising affected users to revoke and audit their Exchange Web Services tokens for unauthorized add-ins and to (1) remove folder permissions to default users, (2) clear the OWA indexDB and PageDataPayload.owaUserDefaultSettings local storage key, and (3) block or alert when machines make outbound connections to command-and-control servers at asecdns[.]com, acocdn[.]com, dnsrecursive[.]eu, and tdndns[.]com.

Offene Fragen

  • Are machines disinfected after Microsoft's July patch?
  • How many organizations are currently compromised?
  • What is the full scope of data stolen by OWAReaper?

Verwandte Themen

This article was originally published by Ars Technica.

Ähnliche Meldungen

Mehr zu diesem Themarussian hackers