A Russia-aligned espionage group, TA488 (also known as Void Blizzard or Laundry Bear), has re-emerged, employing a sophisticated half-click exploit to launch persistent attacks on Outlook Web Access (OWA). Using a cross-site scripting flaw (CVE-2026-42897), they initiated a campaign targeting US and European government entities as well as various sectors including telecommunications and finance.
The group employed mundane email lures and their payload, OWAReaper, operated entirely within the OWA reading pane, allowing it to bypass traditional security measures. Key tactics included server-side persistence, stealing OAuth tokens for elevated privileges, and using a hidden iframe to ensure reinfection after device reimaging. Exfiltration methods included GitHub messages and DNS tunneling, highlighting the group's advanced capabilities. Organizations are urged to implement security updates and revoke specific permissions to mitigate risks.