INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russian Hackers Exploit Zero-Day in Microsoft OWA

| 2026-07-30 07:40 CRITICAL HIGH
Executive Summary AI-generated
The Russian threat actors have linked to the exploitation of a now-patched vulnerability in Zimbra, an email server software used by various organizations. They have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target government entities and sectors such as telecommunications, finance, hospitality, and aerospace. The initial exploit trigger and payload blobs are stored in social media icons, indicating a broad effort to blend in with mass-mailing spam. Data exfiltration is accomplished primarily over HTTPS using AES-CTR encrypted URI paths. OWAReaper runs inside the OWA browser context, operating as a stealthy implant without host footprint. This campaign appears to demonstrate interest in various sectors while prioritizing intelligence collection against government and defense.
Technical Mitigations AI-generated
* Use up-to-date and patched software, such as Microsoft Outlook Web Access (OWA) or Exchange Server, to minimize the risk of exploitation. * Implement robust email security measures, including spam filtering, content filtering, and encryption, to prevent phishing attacks and unauthorized access to mailboxes. * Regularly update and patch operating systems, browsers, and other applications that interact with OWA to ensure they have the latest security fixes. * Use secure communication protocols, such as HTTPS or SFTP, when transferring sensitive information via email or accessing Exchange servers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42897CVE-2026-42897 CVE-2025-66376CVE-2025-66376
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA technologytechnology energyenergy educationeducation mediamedia defensedefense telecommunicationstelecommunications aerospaceaerospace governmentgovernment hospitalityhospitality
Incident Timeline
‎at least July 2025
Russian hackers exploited a zero-day vulnerability in Exchange OWA to target organizations using the Zimbra Collaboration Suite software.
vulnerability CVE-2025-66376
organisation Laundry Bear
organisation CL-STA-1114
source_region Russian Federation
industry Government
attribution the Zimbra Collaboration Suite
attribution ZCS
‎November 2025
Russian hackers used a zero-day vulnerability in ZCS to target Exchange OWA.
vulnerability CVE-2025-66376
organisation The Laundry Bear
organisation ZCS
‎March 2026
Russian hackers exploited Exchange OWA zero-day vulnerability in February 2026.
organisation CVE-2026-42897
‎May 14
Russian hackers exploited the Exchange OWA zero-day vulnerability on May 14.
organisation Microsoft
vulnerability CVE-2026-42897
‎May 2026
Russian hackers exploited Exchange OWA zero-day vulnerability in May 2026.
‎July 22, 2026
Russian hackers exploited the CVE-2026-42897 zero-day vulnerability in Exchange Online Workstation Access (OWA) on July 22, 2026.
vulnerability CVE-2026-42897
general_metric 8.1 score
‎July 23
Russian threat actors exploited an Exchange OWA zero-day vulnerability.
source_region Russian Federation
industry Government
attribution the Zimbra Collaboration Suite
attribution ZCS
‎2026/07/29
Russian hackers exploited Laundry Bear's use of improper HTML sanitization to gain access.
organisation Laundry Bear’s
‎February and July 22, 2026
Russian hackers exploited a recently discovered Exchange OWA zero-day vulnerability.
‎2026/07/30
Russian hackers exploited a zero-day vulnerability in Exchange Outlook Web Access (OWA) to deliver the OWAReaper backdoor.
organisation Russian Hackers
organisation Microsoft
organisation OWA
organisation Keep Mailbox Access After Credential Rotation
organisation Exchange
organisation Russian Hackers Exploit
organisation Laundry Bear
organisation UAC-0190
organisation the Outlook Web Access
organisation HTML
organisation COO
organisation NCSC
organisation DNS
organisation CVE-2026
organisation CVE-2025-66376
organisation ZimReaper
organisation AES
organisation OWAReaper
organisation C&C
organisation Document Object Model
organisation DOM
organisation Owner
organisation Default
organisation the 'Default’
organisation Microsoft Exchange
organisation GitHub
organisation HTTPS
organisation CDN
organisation Analysis
organisation EDR