A newly observed cyber campaign by Russian threat actors has been exploiting a vulnerability in Microsoft Outlook Web Access, also known as OWA, affecting various sectors including government, telecommunications, and finance in the US and Europe. The vulnerability, identified as CVE-2026-42897, is a cross-site scripting flaw in OWA, which allows attackers to maintain access to mailboxes even after credential changes. This exploit, attributed to the group known as Laundry Bear or TA488, uses a JavaScript implant called OWAReaper to gain persistent access by exploiting a 'half-click' method, where merely opening an email triggers the compromise. The exploit is cleverly hidden in generic-themed emails that seem legitimate, increasing the likelihood that recipients will open them without suspicion.

The OWAReaper malware is particularly sophisticated, operating within the OWA browser environment and employing two methods for command-and-control: GitHub and attacker-sent emails. It captures credentials using the browser’s autofill feature, and stores an encrypted version of itself in the browser's localStorage, ensuring it runs every time OWA is opened. This malware can persist even through device re-imaging and credential rotation, necessitating deliberate removal from the Exchange server. Proofpoint, the firm that identified this activity, noted that the campaign's infrastructure has been in place since March 2026, which may indicate that this vulnerability was exploited as a zero-day.

The campaign's focus on a broad range of sectors with a primary interest in government and defense highlights the attackers' strategic intelligence-gathering priorities. The emails used in the campaign are crafted to appear unremarkable, encouraging recipients to open them without suspicion and thereby activate the exploit. The overall approach demonstrates a significant advancement in the threat actors' techniques and capabilities, posing a persistent threat to organizations using Microsoft OWA.