TA488 Exploits Outlook Web Access Flaw to Deploy OWAReaper Mail Implant

Share:

The Russia-aligned espionage group TA488, also called Void Blizzard and Laundry Bear, is running an
email campaign that hijacks Microsoft Outlook Web Access, the browser version of Outlook. Simply
opening one of the rigged emails, a half-click attack with nothing to click, installs a stealthy implant
called OWAReaper that steals mailbox credentials and gives the attacker lasting access to the victim’s
email. The implant survives password resets and device re-imaging, and it has hit government,
telecoms, finance, hospitality, and aerospace targets across the US and Europe.

1. Campaign Timeline

On 22 July 2026, one day before Proofpoint’s joint TA488 release with the NSA, the group began abusing CVE-2026 42897, a cross-site scripting flaw in Outlook Web Access. The volume and breadth of targeting, spanning US and European government, telecommunications, finance, hospitality, and aerospace, was unusually broad for TA488, likely to blend in with mass-mailing spam. Proofpoint attributes the activity to TA488 based on the half-click exploit style, behavioural overlaps with the earlier ZimReaper implant, and its focus on email and credential theft. The earliest infrastructure dates to March 2026, two months before Microsoft’s out-of-band patch, so TA488 may have used the flaw as a zero-day.

2. Attack Details

  • Delivery: TA488 sends emails from a series of compromised accounts, using deliberately bland lures on topics like supply chain, gas-market, or tourism metrics, with no links, attachments, or call to action, so recipients skim and dismiss them.
  • Half-click exploitation: When the message is opened in Outlook Web Access, the Exchange server fails to sanitise the HTML and runs attacker JavaScript. A loader uses the onload event to assemble a Base64 payload hidden in the message’s social-media icons and executes OWAReaper.
  • Execution and cleanup: OWAReaper runs entirely in the OWA reading pane, rewrites the email through Outlook APIs to strip the exploit content, and disables OWA pop-ups and right-click while it operates.
  • Credential and token theft: The implant plants two invisible input fields to capture the browser’s autofilled OWA username and password, then abuses Outlook add-ins with ReadWriteMailbox permissions to call GetClientAccessToken and steal OAuth tokens.

3. Payload Capabilities

OWAReaper is a browser-based implant, an evolution of the earlier ZimReaper, that runs inside the OWA context with no host footprint:

  • Browser persistence: OWAReaper writes an encrypted copy of itself into localStorage under the legitimate PageDataPayload.OwaUserDefaultSettings key, so OWA re-runs it on every tab open, and plants a hidden iframe in the OWA offline IndexedDB cache that re-infects the host even after re-imaging.
  • Server-side persistence: It calls UpdateFolder to grant the low-privilege Default user Owner permissions on every mail folder, giving any authenticated account in the organisation full mailbox access. This foothold survives credential rotation and re-imaging and must be removed from Exchange manually.
  • Command and control: OWAReaper takes commands from crafted GitHub commit messages polled every 24 hours, or from attacker emails polled every 5 minutes, supporting toolkit replacement, C2 rotation, and one-time eval execution.
  • Data exfiltration: It exfiltrates over HTTPS with AES-CTR encrypted paths proxied through image CDNs to acocdn[.]com, falling back to Base32 DNS-label tunnelling, and POSTs stolen files such as the raw OWA session blob unencrypted to acocdn[.]com.

4. Adversary Toolkit

Tool / IndicatorTypeFunction
OWAReaperJavaScript (OWA browser implant)Browser-based Outlook Web Access (OWA) backdoor that steals credentials and OAuth tokens, persists in localStorage and Exchange, and exfiltrates data over HTTPS and DNS.

5. Indicators of Compromise (IOCs)

Type – Indicator
Domain – asecdns[.]com
Domain – acocdn[.]com
Domain – dnsrecursive[.]eu
Domain – tdndns[.]com
SHA256 – 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4

6. Recommendations

  • Apply Microsoft’s out-of-band patch for CVE-2026-42897 to all Exchange and Outlook Web Access servers, following the Microsoft Exchange Team Blog guidance.
  • Audit and remove any Exchange mail-folder permission grants that give the Default user Owner access, since this server-side foothold survives password resets and device re-imaging.
  • On affected endpoints, clear OWA’s IndexedDB cache (owa_offline_db) and the PageDataPayload.OwaUserDefaultSettings localStorage key to remove the browser-resident implant.
  • Revoke and audit Exchange Web Services (EWS) tokens for affected Outlook add-ins, then rotate OWA credentials for affected users after the server-side persistence is removed.
  • Block the IOCs at their respective controls.

7. Sources

  • https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlookanother-half-click-exploit
  • https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulne rability-cve-2026-42897/4518498

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert