RUSSIAN state hackers, identified as TA488, are exploiting a critical vulnerability (CVE-2026-42897) in Microsoft's Exchange Server, allowing them to gain unauthorized access to unpatched networks. This vulnerability, described as a cross-site-scripting flaw, lets attackers execute malicious JavaScript simply by having a victim open a malicious email.
TA488 has developed a new backdoor, named OWAReaper, which runs entirely within the Outlook Web Access (OWA) interface, extracting sensitive information like credentials. Microsoft's mitigation advice, released in May and patched in July, aims to address this vulnerability. Proofpoint advises affected users to take immediate action, including audit of tokens and removal of permissions, to neutralize threats.