Laundry Bear Profile: OWAReaper turns Outlook Web Access email into persistent mailbox access

The Russian state-backed hacking group Laundry Bear, also tracked by Microsoft as Void Blizzard and by Proofpoint as TA488, is accused of exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access to install the OWAReaper backdoor. What stands out is not only the exploitation of enterprise email, but the way the malware can preserve mailbox access even after a password has been changed or a user machine has been fully reinstalled.

Mã JavaScript trong chiến dịch OWAReaper khai thác Outlook Web Access

A new campaign targeting enterprise mailboxes

According to BleepingComputer, the new activity was detected by Proofpoint about a week before publication and targeted multiple organizations, including government agencies in the United States and Europe as well as companies in telecommunications, finance, hospitality, and aerospace. The attack chain exploits CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access that allows JavaScript to run when a victim opens a crafted email.

Proofpoint describes this exploitation pattern as a half-click exploit: users do not need to download an attachment or click a malicious link; simply opening the email in the webmail interface can trigger the exploit code. That is what makes the risk serious for organizations that rely heavily on internal email and self-managed Exchange systems.

From ZimReaper to OWAReaper

Laundry Bear has previously been linked to campaigns exploiting zero-day XSS flaws in Zimbra servers to deploy ZimReaper, a tool used to steal emails, two-factor authentication codes, application passwords, and sensitive mailbox data. With OWAReaper, Proofpoint assesses that the group has significantly upgraded its tradecraft, shifting focus to Microsoft Exchange environments and abusing the way OWA renders email content.

Microsoft warned about CVE-2026-42897 in May 2026. Proofpoint says the infrastructure used for the OWAReaper campaign was built in March, nearly two months before the public warning. This suggests a campaign with longer preparation rather than an opportunistic attack launched only after a patch became public.

How the backdoor persists inside the mailbox

OWAReaper runs entirely inside the Outlook Web Access mail-reading area. Once activated, it uses Outlook APIs to modify the email on the Exchange server, removing the exploit content to reduce the chance of detection. At the same time, the malware can disable pop-ups and right-click actions while it operates.

The malware collects email addresses, usernames, and Outlook settings from the compromised account. One notable technique is creating invisible DOM elements to wait for the browser to autofill credentials, allowing the malware to attempt credential theft when conditions are favorable.

The more dangerous mechanism lies in mailbox permissions. Proofpoint says TA488 can check Outlook add-ins with ReadWriteMailbox privileges, then use GetClientAccessToken to obtain an OAuth token. The malware then calls UpdateFolder to grant Owner rights to the “Default” alias on mail folders, allowing attackers to access the mailbox from any authenticated account in the same organization.

Why changing the password is not enough

If access rights have already been configured on the Exchange server side, changing the user password or reinstalling the workstation does not automatically revoke the permissions planted in the mailbox. This is what makes OWAReaper a particularly dangerous backdoor: the initial trace may appear in the browser and email, but the long-term foothold sits in mailbox configuration.

OWAReaper also has a second persistence mechanism by enabling cache and injecting a malicious iframe into the HTML of emails stored in OWA offline IndexedDB. When the victim reopens the poisoned email from cache, the iframe can continue to execute.

Command channels and data exfiltration

The backdoor supports multiple command channels. One channel uses GitHub commit messages to store encrypted instructions; the malware periodically queries the GitHub Commit Search API to find messages matching the victim email address. Another channel reads email content in IndexedDB using a predefined structure to retrieve commands.

For data exfiltration, the campaign uses HTTPS with AES-CTR-encrypted URI paths and can route traffic through several image CDN domains. If the main channel fails, data can be sent directly to the attacker-controlled server; Proofpoint also observed a fallback mechanism through DNS exfiltration, where data is encrypted and then packaged with Base32.

Lessons for organizations using Exchange

For organizations still running Exchange and Outlook Web Access, the immediate priorities are to verify patch status for CVE-2026-42897, review abnormal mailbox permissions, check add-ins with ReadWriteMailbox privileges, and look for signs that email content was modified after opening. OWA access logs, OAuth token activity, Exchange folder permissions, and unusual GitHub or DNS queries should also be included in threat-hunting scope.

In the longer term, this incident shows that email protection cannot stop at link and attachment filtering. When webmail becomes a code-execution surface, an ordinary-looking email can still become the starting point for persistent mailbox control. Security teams need to combine rapid patching, mailbox behavior monitoring, add-in governance, and server-side permission revocation after an incident.

VNCyberS compiled from BleepingComputer, Proofpoint, and Microsoft

Contact Us

Email: [email protected]
Phone: +84 903260277