TA488 Half-Click Exploit Moves to Outlook Web Access Flaw, Deploys Persistent OWAReaper Backdoor
- Half-click exploit: TA488 exploited CVE-2026-42897 in Outlook Web Access, allowing malicious JavaScript to execute when a victim simply opened a crafted email in OWA.
- New implant: Proofpoint identified OWAReaper, a browser-based backdoor designed to maintain persistence even after credential resets or device re-imaging.
- Targeted sectors: The campaign affected government, telecommunications, finance, hospitality, and aerospace organizations across the United States and Europe.
Proofpoint has uncovered a cyberespionage campaign by TA488, a Russia-aligned threat group also tracked as Void Blizzard, Laundry Bear, CL-STA-1114, and TA488 (formerly UNK_PitStop), exploiting a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) to deploy a newly identified browser-based implant named OWAReaper.
Void Blizzard was seen leveraging half-click XSS zero-days against Zimbra, with other Russian spies also exploiting mDaemon, SOGo, and Roundcube. The new wave of exploitation began exploiting CVE-2026-42897 on July 22, one day before Proofpoint and the U.S. National Security Agency (NSA) publicly disclosed the vulnerability.
CVE-2026-42897 Enables 'Half-Click' Outlook Web Access Attacks
Proofpoint describes the attack as a "half-click" exploit because victims only need to open a specially crafted email in OWA for the malicious code to execute, without the need to click links or open attachments.
According to the researchers, the vulnerability causes the Exchange server to improperly process HTML content within the email, allowing arbitrary JavaScript to run inside the victim's OWA session. The attackers used this behavior to install OWAReaper, a browser-resident backdoor that operates entirely within the OWA environment.
“Compared to TA488’s previous Zimbra targeting, the payload storage in the message body is more subtle and harder to discern,” the report said.
OWAReaper Uses Server-Side Persistence to Survive Credential Resets
Once deployed, OWAReaper stores an encrypted copy of itself in the browser's localStorage, modifies OWA's offline message cache with a hidden iframe, and grants Owner-level Exchange folder permissions to the Default user. Proofpoint said this combination allows the implant to maintain access even after browser reboots, credential rotation, and full device re-imaging.
The malware implements two data exfiltration protocols:
- over HTTPS with AES-CTR encrypted URI paths, using services including Weserv.nl, WordPress (i3.wp.com), and Slack image CDNs.
- DNS exfiltration as a fallback when the HTTPS method fails.
Timeline Suggests TA488 Had Early Access to the Vulnerability
Proofpoint's investigation found infrastructure associated with the campaign dating back to March 2026, approximately two months before Microsoft released its out-of-band security update for CVE-2026-42897. Based on that timeline, the researchers said the activity suggests TA488 may have had access to the vulnerability before the public patch became available.
The campaign targeted organizations in the U.S. and Europe, including government agencies, telecommunications providers, financial institutions, hospitality companies, and aerospace organizations.
Organizations using Microsoft Exchange and OWA should ensure the relevant security updates have been applied and review Proofpoint's published indicators of compromise and detection guidance.









