TA 488, a Russia-aligned cyber-espionage group, utilized a half-click exploit (CVE-2026-42897) targeting Outlook Web Access (OWA) to deploy a browser implant named OWAReaper. The campaign, launched on July 22, 2026, aimed at US and European government, telecom, finance, hospitality, and aerospace sectors, marking a broad attack strategy.
Key characteristics include the exploit allowing installation without user interaction (just opening an email), and the malware's persistent nature, as it embeds itself within OWA settings. OWAReaper harvests sensitive OWA credentials and executes commands via encrypted channels. To mitigate risks, immediate patching and auditing are recommended.