TA488 half-click Outlook Web Access espionage campaign
Campaign
Summary
Hide ▲
Show ▼
TA488 resurfaced on July 22 with a half-click OWA exploit that put government and industry targets at risk of account takeover and durable mailbox access. The operation abused CVE-2026-42897 on on-premises Exchange Server, executing JavaScript inside an authenticated session. Its OWAReaper implant could steal credentials and OAuth tokens, then maintain server-side persistence that survived credential rotation and device re-imaging. Exfiltration used HTTPS through image CDNs with DNS tunneling as a fallback.
Related Happenings
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
H score34
First: 24.07.2026 20:50
Last: 24.07.2026 20:50
Sources 1
About this happening:
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
CampaignAbout this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Microsoft security patch release for CVE-2026-42897
Security Patch Release
H score44
First: 10.06.2026 16:44
Last: 10.06.2026 16:44
Sources 1
About this happening:
Microsoft released June 2026 Security Updates for Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) to fix CVE-2026-4...
Microsoft security patch release for CVE-2026-42897
Security Patch ReleaseAbout this happening: Microsoft released June 2026 Security Updates for Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) to fix CVE-2026-4...
Microsoft security patch release for CVE-2026-45586
Security Patch Release
H score41
First: 09.06.2026 20:57
Last: 09.06.2026 20:57
Sources 1
How related:
The messages exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server, not Exchange Online.
About this happening:
Microsoft's June 2026 Patch Tuesday delivers 200 flaw fixes across Windows and related products, including six zero-days and one actively exploited vulnerability....
Microsoft security patch release for CVE-2026-45586
Security Patch ReleaseHow related: The messages exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server, not Exchange Online.
About this happening: Microsoft's June 2026 Patch Tuesday delivers 200 flaw fixes across Windows and related products, including six zero-days and one actively exploited vulnerability....
Microsoft Exchange CVE-2026-42897 mitigation advisory
Advisory/Mitigation
H score44
First: 15.05.2026 12:40
Last: 15.05.2026 12:40
Sources 1
About this happening:
Microsoft issued immediate mitigation guidance for CVE-2026-42897, reducing risk for Exchange Server 2016, 2019, and Subscription Edition (SE) on-premises servers that...
Microsoft Exchange CVE-2026-42897 mitigation advisory
Advisory/MitigationAbout this happening: Microsoft issued immediate mitigation guidance for CVE-2026-42897, reducing risk for Exchange Server 2016, 2019, and Subscription Edition (SE) on-premises servers that...
Latest development: 15.05.2026 15:35
Microsoft issued temporary mitigation guidance for CVE-2026-42897 while a patch is still in development, recommending the Exchange Emergency Mitigation (EM) Service, which is enabled by default and can be checked with the Exchange Health Checker script, or the Exchange On-premises Mitigation Tool (EOMT) for disconnected or air-gapped environments. Microsoft noted that the mitigations can disrupt features such as OWA Print Calendar and Inline images, and that servers older than March 2023 cannot receive new mitigations through EM Service.
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
Vulnerability
H score37
First: 15.05.2026 09:19
Last: 15.05.2026 09:19
Sources 1
How related:
The messages exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server, not Exchange Online.
About this happening:
CVE-2026-42897 is an actively exploited cross-site scripting flaw in on-premises Microsoft Exchange Server that lets a specially crafted email opened in Outlook...
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
VulnerabilityHow related: The messages exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server, not Exchange Online.
About this happening: CVE-2026-42897 is an actively exploited cross-site scripting flaw in on-premises Microsoft Exchange Server that lets a specially crafted email opened in Outlook...
Latest development: 09.06.2026 20:57
Microsoft identifies CVE-2026-42897 in Microsoft Exchange Server as an actively exploited spoofing vulnerability that can lead to JavaScript execution in a target’s browser when a specially crafted email is opened in Outlook Web Access under certain interaction conditions. Microsoft says mitigations are being pushed through the Exchange Emergency Mitigation Service while it continues work on the full update.
Timeline
-
29.07.2026 18:10 2 articles · 1h ago
TA488 begins half-click OWA campaign against on-premises Exchange Server
Exploitation ObservedTA488, also tracked as Void Blizzard and Laundry Bear, began a campaign on July 22, 2026 that used a half-click exploit against on-premises Outlook Web Access (OWA) on Exchange Server. The messages exploited CVE-2026-42897 to execute JavaScript inside the victim's authenticated session and deploy the browser-resident implant OWAReaper against US and European government entities and organizations in telecommunications, financial, hospitality, and aerospace.
Show sources
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10
-
29.07.2026 18:10 1 articles · 1h ago
Proofpoint details OWAReaper persistence and Microsoft releases Exchange security updates
Technical Analysis UpdateOn July 29, 2026, Proofpoint detailed OWAReaper as a JavaScript implant that ran in the OWA reading pane with no conventional file on disk, rewrote the original email on the server, hid encrypted code in browser localStorage, and used a hidden iframe in OWA's offline IndexedDB cache to re-infect a re-imaged host. The report also described server-side mailbox persistence through OAuth token theft and Default-user folder grants, and noted that Microsoft had released Exchange security updates while recommending Exchange Web Services token revocation, removal of unauthorized folder grants, and clearing OWA offline storage.
Show sources
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10