www.infosecurity-magazine.com 7/29/2026, 3:20:43 PM · external

TA488 employs half‑click OWA exploit against government targets

TA488 employs half‑click OWA exploit against government targets
Developing story vulnerability 3 articles tracked
TA488 exploits CVE-2026-42897 to deploy OWAReaper in Outlook
CyberSIXT Evidence Panel
Primary Source proofpoint.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
TA488

A Russia-aligned espionage group, TA488 (also known as Void Blizzard or Laundry Bear), has re-emerged, employing a sophisticated half-click exploit to launch persistent attacks on Outlook Web Access (OWA). Using a cross-site scripting flaw (CVE-2026-42897), they initiated a campaign targeting US and European government entities as well as various sectors including telecommunications and finance.

The group employed mundane email lures and their payload, OWAReaper, operated entirely within the OWA reading pane, allowing it to bypass traditional security measures. Key tactics included server-side persistence, stealing OAuth tokens for elevated privileges, and using a hidden iframe to ensure reinfection after device reimaging. Exfiltration methods included GitHub messages and DNS tunneling, highlighting the group's advanced capabilities. Organizations are urged to implement security updates and revoke specific permissions to mitigate risks.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline