Skip to content
Malware

TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch

TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a now-patched cross-site scripting flaw, tracked as CVE-2026-42897, and could run malicious code when a recipient opened a message in the webmail interfac...

· Jul 30, 2026 · 4 min read · 👁 4 views
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch

TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise.

The operation abused a now-patched cross-site scripting flaw, tracked as CVE-2026-42897, and could run malicious code when a recipient opened a message in the webmail interface.

The campaign targeted government bodies and organizations in telecommunications, finance, hospitality, and aerospace across the United States and Europe.

Unlike common phishing attacks, the emails did not need a harmful attachment or a link, making them easier to overlook in a busy inbox.

Analysts at Proofpoint identified the activity and named the browser-based implant OWAReaper.

Proofpoint said in a report shared with Cyber Security News (CSN) that the group had improved the loading, persistence, and data theft capabilities used in its half-click attacks.

The finding adds urgency to the wider response to the Outlook Web Access flaw.

Earlier reporting on the Microsoft Exchange server vulnerability noted that the issue affected on-premises Exchange deployments and allowed attacker-controlled JavaScript to execute in an authenticated user’s browser session.

TA488 May Have Exploited Outlook Web Access 0-Day Flaw

TA488 began exploiting CVE-2026-42897 on July 22, 2026, according to the researchers.

The campaign appeared just before public reporting tied the Russia-aligned group, also known as Void Blizzard and Laundry Bear, to earlier attacks against webmail platforms.

The group used compromised accounts to distribute vague messages about supply chains, energy, tourism, public health, and market metrics.

These subjects were designed to look ordinary enough for recipients to open and briefly review, rather than immediately report as suspicious.

TA488 “Semiconductor Supply Chain” lure email from July 2026 (Source - Proofpoint)
TA488 “Semiconductor Supply Chain” lure email from July 2026 (Source – Proofpoint)

When a victim opened the email in Outlook Web Access, the Exchange server failed to safely handle parts of the message’s HTML content.

That mistake let a hidden JavaScript loader reconstruct and run the OWAReaper payload directly inside the browser’s Outlook session.

Researchers said the oldest infrastructure associated with the operation was created in March 2026, about two months before Microsoft issued its emergency response for the vulnerability.

That timing means TA488 may have had access to the flaw as a zero-day before defenders could apply protections.

Microsoft later issued permanent updates for affected supported Exchange versions, while CISA urged organizations to apply available updates and mitigations quickly.

Organizations should also review their exposure to internet-facing Exchange systems, as outlined in the CISA Exchange vulnerability warning.

OWAReaper Builds Persistence

OWAReaper operates entirely within the Outlook Web Access browser environment, leaving little or no traditional malware footprint on the endpoint.

It can collect mailbox details, user settings, and saved browser credentials, then store an encrypted copy of itself in Outlook-related browser storage.

JavaScript triggered by mishandled HTML sanitization (Source - Proofpoint)
JavaScript triggered by mishandled HTML sanitization (Source – Proofpoint)

The implant also attempts to change mailbox folder permissions, potentially giving a low-privileged default account owner-level access to folders.

This server-side access can survive password resets or a full rebuild of the victim’s computer unless administrators deliberately remove the altered permissions.

TA488 OWAReaper infection chain (Source - Proofpoint)
TA488 OWAReaper infection chain (Source – Proofpoint)

For command handling, OWAReaper can retrieve encrypted instructions from crafted GitHub commit messages or parse commands delivered through incoming email.

It can also use HTTPS traffic routed through image delivery services, with DNS tunneling as a fallback method for sending stolen information.

The most important response is to install the relevant Exchange updates and retain compensating protections where required.

Security teams should revoke and audit Exchange Web Services tokens for affected add-ins, remove improper Default-user folder permissions, clear affected Outlook browser storage, and monitor or block connections to known command-and-control infrastructure.

This campaign shows why email-borne attacks cannot be judged only by attachments and links.

Security teams should investigate unexpected Outlook Web Access behavior, including suspicious scripts, unusual permission changes, and anomalous webmail sessions, while continuing to educate users about deceptive but seemingly harmless messages.

The risks of weaponized mail remain clear in recent phishing email campaigns, even when the delivery methods differ.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domainasecdns[.]comOWAReaper command-and-control infrastructure
Domainacocdn[.]comOWAReaper command-and-control infrastructure and HTTPS data relay
Domaindnsrecursive[.]euOWAReaper command-and-control infrastructure
Domaintdndns[.]comOWAReaper command-and-control infrastructure
SHA-2566897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4HTML message body containing the exploit and OWAReaper payload

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you