Threat actor
TA488
Tracked by CyberSIXT since Jul 23, 2026 · last activity Jul 30, 2026
Associated CVEs
Coverage timeline
-
Russian hackers use Exchange XSS bug to plant OWAReaperarstechnica.com · Jul 30, 2026
-
TA488 employs half‑click OWA exploit against government targetswww.infosecurity-magazine.com · Jul 29, 2026
-
TA488 leverages CVE-2026-42897 to plant OWAReaper in Outlooksecurityonline.info · Jul 29, 2026
-
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploitssecurityonline.info · Jul 23, 2026