Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
A Russian state-linked group is targeting government agencies, telecoms, banks, and aerospace firms across the US and Europe — and changing your password is not enough to stop them, according to Proofpoint's research.
The group, tracked as Laundry Bear and also known as TA488 and Void Blizzard, is exploiting CVE-2026-42897 (CVSS score: 8.1 — High), a cross-site scripting (XSS) [a flaw that lets attackers inject malicious code into web pages viewed by others] vulnerability in Microsoft Outlook Web Access (OWA), which is the browser-based version of Outlook used by many corporate and government email systems.
The attack requires no clicks. Opening the email is enough.
Victims receive a message disguised as routine business correspondence — supply chain reports, tourism statistics, market updates. No suspicious links, no attachments. Just an ordinary-looking email. When OWA renders it, the exploit fires automatically, loading a hidden JavaScript payload assembled from fragments hidden inside social media icons and image data in the message HTML.
That payload installs a browser-based implant called OWAReaper. It immediately removes the exploit content from the email on the server — erasing evidence of the intrusion — then creates a persistent session key tied to the victim. From that point, the attacker retains access to the mailbox even if the victim rotates credentials, because the session itself, not the password, is what keeps the door open.
The malware also harvests email history and disables right-click menus and pop-ups while it runs.
What to do: If your organisation uses OWA, contact your IT or security team today and ask whether CVE-2026-42897 has been patched. Individually, check whether your email provider has pushed updates and review any active sessions in your account security settings — terminate everything you do not recognise.
Sources

