INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian Hackers Exploit Zero-Day in Microsoft OWA
| 2026-07-30 07:40 CRITICAL HIGHExecutive Summary AI-generated
The Russian threat actors have linked to the exploitation of a now-patched vulnerability in Zimbra, an email server software used by various organizations. They have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target government entities and sectors such as telecommunications, finance, hospitality, and aerospace. The initial exploit trigger and payload blobs are stored in social media icons, indicating a broad effort to blend in with mass-mailing spam. Data exfiltration is accomplished primarily over HTTPS using AES-CTR encrypted URI paths. OWAReaper runs inside the OWA browser context, operating as a stealthy implant without host footprint. This campaign appears to demonstrate interest in various sectors while prioritizing intelligence collection against government and defense.
Technical Mitigations AI-generated
* Use up-to-date and patched software, such as Microsoft Outlook Web Access (OWA) or Exchange Server, to minimize the risk of exploitation.
* Implement robust email security measures, including spam filtering, content filtering, and encryption, to prevent phishing attacks and unauthorized access to mailboxes.
* Regularly update and patch operating systems, browsers, and other applications that interact with OWA to ensure they have the latest security fixes.
* Use secure communication protocols, such as HTTPS or SFTP, when transferring sensitive information via email or accessing Exchange servers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42897CVE-2026-42897
CVE-2025-66376CVE-2025-66376
Target & Sectors
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
energyenergy
educationeducation
mediamedia
defensedefense
telecommunicationstelecommunications
aerospaceaerospace
governmentgovernment
hospitalityhospitality
Incident Timeline
at least July 2025
Russian hackers exploited a zero-day vulnerability in Exchange OWA to target organizations using the Zimbra Collaboration Suite software.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
Enterprise security company Proofpoint has attributed the activity to
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard), which was recently attributed to the zero-day exploitation of CVE-2025-66376, an XSS flaw in Zimbra's Classic UI, since at least July 2025 before it was patched four months later.
organisation
Laundry Bear
Enterprise security company Proofpoint has attributed the activity to
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard), which was recently attributed to the zero-day exploitation of CVE-2025-66376, an XSS flaw in Zimbra's Classic UI, since at least July 2025 before it was patched four months later.
organisation
CL-STA-1114
Enterprise security company Proofpoint has attributed the activity to
Laundry Bear
(aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard), which was recently attributed to the zero-day exploitation of CVE-2025-66376, an XSS flaw in Zimbra's Classic UI, since at least July 2025 before it was patched four months later.
source_region
Russian Federation
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
industry
Government
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
attribution
the Zimbra Collaboration Suite
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
attribution
ZCS
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
November 2025
Russian hackers used a zero-day vulnerability in ZCS to target Exchange OWA.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data.
organisation
The Laundry Bear
The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data.
organisation
ZCS
The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data.
March 2026
Russian hackers exploited Exchange OWA zero-day vulnerability in February 2026.
Click on any entity below to view its context and source!
organisation
CVE-2026-42897
Proofpoint noted that the earliest infrastructure used in this campaign was created in March 2026, two months before Microsoft disclosed CVE-2026-42897, raising the possibility that it may have been exploited as a zero-day.
May 14
Russian hackers exploited the Exchange OWA zero-day vulnerability on May 14.
Click on any entity below to view its context and source!
organisation
Microsoft
Based on Microsoft’s advisory on May 14 for the CVE-2026-42897 flaw in OWA, the threat actor was already
exploiting it as a zero-day
.
vulnerability
CVE-2026-42897
Based on Microsoft’s advisory on May 14 for the CVE-2026-42897 flaw in OWA, the threat actor was already
exploiting it as a zero-day
.
May 2026
Russian hackers exploited Exchange OWA zero-day vulnerability in May 2026.
July 22, 2026
Russian hackers exploited the CVE-2026-42897 zero-day vulnerability in Exchange Online Workstation Access (OWA) on July 22, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-42897
The activity, which began on July 22, 2026, involves the weaponization of
CVE-2026-42897
(CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA.
general_metric
8.1 score
The activity, which began on July 22, 2026, involves the weaponization of
CVE-2026-42897
(CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA.
July 23
Russian threat actors exploited an Exchange OWA zero-day vulnerability.
Click on any entity below to view its context and source!
source_region
Russian Federation
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
industry
Government
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
attribution
the Zimbra Collaboration Suite
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
attribution
ZCS
Issued on July 23
, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.
2026/07/29
Russian hackers exploited Laundry Bear's use of improper HTML sanitization to gain access.
Click on any entity below to view its context and source!
organisation
Laundry Bear’s
Improper HTML sanitization
In a new report today, Proofpoint describes Laundry Bear’s new half-click exploit campaign as a significant “improvement in the group’s tradecraft and capability.”
February and July 22, 2026
Russian hackers exploited a recently discovered Exchange OWA zero-day vulnerability.
2026/07/30
Russian hackers exploited a zero-day vulnerability in Exchange Outlook Web Access (OWA) to deliver the OWAReaper backdoor.
Click on any entity below to view its context and source!
organisation
Russian Hackers
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation.
organisation
Microsoft
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation.
organisation
OWA
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
organisation
Keep Mailbox Access After Credential Rotation
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation.
organisation
Exchange
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access.
Once executed, it uses Outlook APIs to rewrite the email on the Exchange server and remove the exploit content.
organisation
Russian Hackers Exploit
Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations.
organisation
Laundry Bear
The campaign has been attributed to cyber espionage operation which has been linked to Russia dubbed Laundry Bear, also known as
Void Blizzard
and UAC-0190.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
organisation
UAC-0190
The campaign has been attributed to cyber espionage operation which has been linked to Russia dubbed Laundry Bear, also known as
Void Blizzard
and UAC-0190.
organisation
the Outlook Web Access
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
organisation
HTML
"The initial exploit trigger and relevant payload blobs are stored in the social media icons shown in the message body HTML.
The security issue causes the server to improperly sanitize the HTML code in the message body, which could be leveraged to run JavaScript when opening the email.
organisation
COO
“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said Beth Hopkins, COO of the NCSC.
organisation
NCSC
“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said Beth Hopkins, COO of the NCSC.
organisation
DNS
There is also a DNS exfiltration fallback, where data is encrypted, then encoded in packets using the Base32 method.
Should this approach fail, the malware uses DNS label tunneling to smuggle data within standard DNS queries of an actor-controlled domain.
organisation
CVE-2026
"
The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client.
organisation
CVE-2025-66376
In these attacks, the threat actors sent out messages from adversary-controlled Proton Mail accounts and from previously compromised addresses that triggered an exploit for CVE-2025-66376 as soon as the emails were viewed via a vulnerable version of Zimbra, ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
organisation
ZimReaper
In these attacks, the threat actors sent out messages from adversary-controlled Proton Mail accounts and from previously compromised addresses that triggered an exploit for CVE-2025-66376 as soon as the emails were viewed via a vulnerable version of Zimbra, ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
Previously, the same hackers leveraged another XSS vulnerability (CVE-2025-66376) as a
zero-day in Zimbra email servers
to deliver malware ZimReaper that steals email communication, two-factor authentication (2FA) codes, application passcodes, and passwords.
organisation
AES
If it finds one, the data is parsed and decrypted using a hard-coded key from the JavaScript and a per-session AES key, likely in an attempt to prevent other parties from extracting the commands.
Laundry Bear also used two methods to exfiltrate data, the main one using HTTPS with AES-CTR encrypted URI paths that would be proxied through certain image content delivery network (CDN) domains.
organisation
OWAReaper
The decoded data contains a four-character header that denotes a specific command type -
code, to replace OWAReaper's entire toolkit code
domn, to rotate the C&C servers
cmnd, to execute arbitrary JavaScript code via eval()
Alternatively, OWAReaper can parse inbound emails sent from TA488 operators to process and run the same types of commands observed in the GitHub method.
According to Proofpoint, Laundry Bear, which the company tracks as TA488, had created the attack infrastructure for the OWAReaper campaign in March, almost two months before Microsoft’s warning.
organisation
C&C
The decoded data contains a four-character header that denotes a specific command type -
code, to replace OWAReaper's entire toolkit code
domn, to rotate the C&C servers
cmnd, to execute arbitrary JavaScript code via eval()
Alternatively, OWAReaper can parse inbound emails sent from TA488 operators to process and run the same types of commands observed in the GitHub method.
organisation
Document Object Model
It then creates two invisible input elements in the web page's Document Object Model (DOM) so as to capture the victim's OWA saved credentials via the browser's autofill feature.
organisation
DOM
It then creates two invisible input elements in the web page's Document Object Model (DOM) so as to capture the victim's OWA saved credentials via the browser's autofill feature.
It also tries to steal the access credentials by creating invisible elements in the Document Object Model (DOM) and waiting for the browser to automatically fill them in.
organisation
Owner
OWAReaper checks for installed Outlook add-ins with ReadWriteMailbox permissions, and, if found, uses them to steal OAuth tokens, and grants itself Owner-level permissions to the Default user on every mail folder.
“It then calls UpdateFolder to grant itself Owner-level permissions to the 'Default’ user (a low-permission preset alias in all Microsoft Exchange tenants) on every mail folder,” the researchers explain.
organisation
Default
OWAReaper checks for installed Outlook add-ins with ReadWriteMailbox permissions, and, if found, uses them to steal OAuth tokens, and grants itself Owner-level permissions to the Default user on every mail folder.
organisation
the 'Default’
“It then calls UpdateFolder to grant itself Owner-level permissions to the 'Default’ user (a low-permission preset alias in all Microsoft Exchange tenants) on every mail folder,” the researchers explain.
organisation
Microsoft Exchange
“It then calls UpdateFolder to grant itself Owner-level permissions to the 'Default’ user (a low-permission preset alias in all Microsoft Exchange tenants) on every mail folder,” the researchers explain.
organisation
GitHub
The script queries GitHub's Commit Search API every 24 hours for commit messages containing the target's email address.
Every 24 hours, the malware queries GitHub's Commit Search API for encrypted messages that match a specific format and include the target's email address.
organisation
HTTPS
Laundry Bear also used two methods to exfiltrate data, the main one using HTTPS with AES-CTR encrypted URI paths that would be proxied through certain image content delivery network (CDN) domains.
organisation
CDN
Laundry Bear also used two methods to exfiltrate data, the main one using HTTPS with AES-CTR encrypted URI paths that would be proxied through certain image content delivery network (CDN) domains.
organisation
Analysis
Analysis revealed a “suite of subtle persistence mechanisms” and revealed it to be an evolution of the ZimReaper malware observed in the attacks against Zimbra email servers.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Intelligence Sources
Infosecurity-Magazine
2026-07-23
Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
Infosecurity-Magazine
BleepingComputer
2026-07-29
The Hacker News
2026-07-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-30T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
35x
organisation
Identified Entity
Russian Hackers
entity
11x
timeline
Temporal Reference
July 22, 2026
date
9x
industry
Targeted Sector
Government
sector
8x
attribution
Attributing Entity
Microsoft Outlook Web Access
authority
4x
target region
Target Country
Russian Federation
country
3x
source region
Origin Country
Russian Federation
country
3x
tactic
Cyber Operation Type
Phishing
tactic
2x
vulnerability
Exploited CVE
CVE-2026-42897
cve
2x
target region
Target Region
EUROPE
region
2x
general metric
%
54
%
Contextual Telemetry
Context Block
3 METRICS
general metric
Score
8
score
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
general metric
Hours
24
hours
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.