TA488 Half-Click Exploit Moves to Outlook Web Access Flaw, Deploys Persistent OWAReaper Backdoor

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Half-click exploit: TA488 exploited CVE-2026-42897 in Outlook Web Access, allowing malicious JavaScript to execute when a victim simply opened a crafted email in OWA.
  • New implant: Proofpoint identified OWAReaper, a browser-based backdoor designed to maintain persistence even after credential resets or device re-imaging.
  • Targeted sectors: The campaign affected government, telecommunications, finance, hospitality, and aerospace organizations across the United States and Europe.

Proofpoint has uncovered a cyberespionage campaign by TA488, a Russia-aligned threat group also tracked as Void Blizzard, Laundry Bear, CL-STA-1114, and TA488 (formerly UNK_PitStop), exploiting a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) to deploy a newly identified browser-based implant named OWAReaper.

Void Blizzard was seen leveraging half-click XSS zero-days against Zimbra, with other Russian spies also exploiting mDaemon, SOGo, and Roundcube. The new wave of exploitation began exploiting CVE-2026-42897 on July 22, one day before Proofpoint and the U.S. National Security Agency (NSA) publicly disclosed the vulnerability.

CVE-2026-42897 Enables 'Half-Click' Outlook Web Access Attacks

Proofpoint describes the attack as a "half-click" exploit because victims only need to open a specially crafted email in OWA for the malicious code to execute, without the need to click links or open attachments.

TA488 “Semiconductor Supply Chain” lure email from July 2026 | Source: Proofpoint
TA488 “Semiconductor Supply Chain” lure email from July 2026 | Source: Proofpoint

According to the researchers, the vulnerability causes the Exchange server to improperly process HTML content within the email, allowing arbitrary JavaScript to run inside the victim's OWA session. The attackers used this behavior to install OWAReaper, a browser-resident backdoor that operates entirely within the OWA environment.

Compared to TA488’s previous Zimbra targeting, the payload storage in the message body is more subtle and harder to discern,” the report said.

OWAReaper Uses Server-Side Persistence to Survive Credential Resets

Once deployed, OWAReaper stores an encrypted copy of itself in the browser's localStorage, modifies OWA's offline message cache with a hidden iframe, and grants Owner-level Exchange folder permissions to the Default user. Proofpoint said this combination allows the implant to maintain access even after browser reboots, credential rotation, and full device re-imaging.

TA488 OWAReaper infection chain | Source: Proofpoint
TA488 OWAReaper infection chain | Source: Proofpoint

The malware implements two data exfiltration protocols:

HTTPS exfiltration method | Source: Proofpoint
HTTPS exfiltration method | Source: Proofpoint

Timeline Suggests TA488 Had Early Access to the Vulnerability

Proofpoint's investigation found infrastructure associated with the campaign dating back to March 2026, approximately two months before Microsoft released its out-of-band security update for CVE-2026-42897. Based on that timeline, the researchers said the activity suggests TA488 may have had access to the vulnerability before the public patch became available.

The campaign targeted organizations in the U.S. and Europe, including government agencies, telecommunications providers, financial institutions, hospitality companies, and aerospace organizations.

Organizations using Microsoft Exchange and OWA should ensure the relevant security updates have been applied and review Proofpoint's published indicators of compromise and detection guidance.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: