bleeping-computer · Crawled Jul 30, 2026

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

8 IoCs 1 Actors 1 CVEs
Read original article ↗

AI Summary

Russian state-sponsored threat actor Laundry Bear (also known as Void Blizzard or TA488) is exploiting a zero-day cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Microsoft Exchange Outlook Web Access (OWA) to deliver a sophisticated backdoor called OWAReaper. This 'half-click' exploit requires only that the user open a malicious email, which executes JavaScript due to improper HTML sanitization, enabling deployment of the payload without user interaction. OWAReaper establishes long-term persistence by abusing Outlook add-ins to steal OAuth tokens and granting Owner-level permissions to mail folders via the Default user, allowing continued access even after credential resets or system reimaging. The malware uses multiple command-and-control mechanisms, including GitHub commit messages and email parsing, and supports multiple data exfiltration methods, including encrypted HTTPS and DNS tunneling.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 8 extracted

Type Value Detail
Domain cddis[.]nasa[.]gov Details →
Domain gssc[.]esa[.]int Details →
Domain igs[.]org Details →
Domain sideshowbob[.]on[.]torproject[.]org Details →
GitHub Repo sideshowbob/on.torproject.org Details →
GitHub User sideshowbob Details →
Filename OWAReaper Details →
Filename ZimReaper Details →

MITRE ATT&CK TTPs 39 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development