1. Executive summary
The Russian state-linked APT group Laundry Bear (also tracked as TA488 / Void Blizzard) has been observed exploiting a vulnerability in Microsoft Outlook Web Access (OWA), tracked as CVE-2026-42897, to deploy a novel JavaScript backdoor dubbed OWAReaper. Proofpoint reports the campaign began around March 2026, targeting US and European government entities and the telecommunications, financial, hospitality, and aerospace sectors. The infection chain uses "half-click" exploits — requiring only that a target open an email — and the resulting implant provides persistent access inside OWA for email and credential theft. The vulnerability was first publicised and patched in May 2026, with Microsoft posting remediation information in mid-July. Attribution to Laundry Bear is unconfirmed: the actor has no MITRE ATT&CK profile in the verified reference data. The entire technical detail in this advisory is single-sourced to Proofpoint.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | A targeted espionage campaign actively exploiting a zero-day-class OWA vulnerability against the financial sector to steal emails and credentials constitutes a major cyber threat relevant to incident classification. | If a client's OWA environment was compromised or targeted, assess whether the incident meets the classification and reporting thresholds under DORA Art. 18–19. |
| DORA Art. 24: digital operational resilience testing — general requirements | The exploitation vector is a known CVE (CVE-2026-42897) patched in May 2026 with Microsoft remediation guidance posted in mid-July; unpatched OWA instances represent a failed resilience posture. | Verify OWA patch levels against the May 2026 fix; incorporate this CVE into vulnerability management and penetration testing programmes. |
3. Technical analysis & attack chain
Confidence caveat: All technical detail below is single-sourced to Proofpoint reporting (via The Record, 2026-07-29). No independent corroboration is available. Attribution to Laundry Bear / TA488 / Void Blizzard is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. Treat attribution and capability claims with appropriate caution.
- Targeting and scope. Laundry Bear targeted US and European government entities and the telecommunications, financial, hospitality, and aerospace sectors. The operational goal was theft of emails and account credentials — consistent with the group's earlier Zimbra webmail campaign.
- Initial access via "half-click" exploit. The group used "half-click" exploits against Microsoft OWA, meaning that simply opening an email was sufficient to trigger the infection chain — no attachment interaction or link click was required. Proofpoint assesses it is "feasible" that Laundry Bear was exploiting the vulnerability as a zero-day during the campaign period, which began in March 2026. The vulnerability, CVE-2026-42897, was first publicised and patched in May 2026; Microsoft posted remediation information in mid-July 2026.
- Payload delivery. The infection chain delivers a previously unknown JavaScript browser-based implant that Proofpoint calls OWAReaper. The implant is purpose-built for persistent access inside OWA.
- Persistence. OWAReaper employs what Proofpoint describes as a "suite of subtle persistence mechanisms" within the OWA environment. No further technical detail on the specific persistence mechanisms (registry keys, scheduled tasks, file modifications) is available in the source material. Proofpoint rates OWAReaper as "the most sophisticated backdoor delivered via half-click exploits" they have observed, primarily due to these persistence capabilities.
- Objectives and impact. The implant enables persistent access inside OWA for ongoing email and credential theft. Proofpoint characterises the campaign as representing "an improvement in the group's tradecraft and capability."
No further technical specifics (exact OWA versions affected, CVE mechanism details, C2 infrastructure, file paths, command-line artefacts, or additional malware capabilities) are available in the provided source material.
4. Mitigation & containment
P1 — Within 24 hours
- Identify all internet-facing Microsoft OWA instances in the estate and confirm patch status against CVE-2026-42897. Microsoft posted remediation information in mid-July 2026; apply the relevant patch immediately to any unpatched instance.
- Review OWA and Exchange logs from March 2026 onward for anomalous authentication patterns, unexpected session persistence, or suspicious JavaScript execution within the OWA context.
P2 — Within 72 hours
- If OWA cannot be patched immediately, consider restricting external access to OWA via VPN or IP allowlisting as a temporary containment measure.
- Audit OWA service accounts and mailbox permissions for signs of unauthorised access or credential compromise. Reset credentials for any accounts showing anomalous session activity.
- Brief email security and SOC teams on the "half-click" delivery model — standard email gateway filtering for malicious attachments and links will not detect this vector.
P3 — Within 7 days
- Ensure vulnerability management processes incorporate rapid assessment of Microsoft Exchange/OWA CVEs given the active targeting of this attack surface by state-linked actors.
- Review email security architecture to determine whether OWA should remain internet-facing for populations that do not require remote webmail access.
5. Indicators of compromise
No atomic indicators of compromise (IPs, domains, hashes, file paths, URLs) are available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Anomalous or persistent OWA sessions following email open (no click required) | OWA/Exchange IIS logs, authentication logs | Medium — single-sourced to Proofpoint |
| JavaScript execution or injection within the OWA browser context | EDR on OWA-facing servers, browser telemetry if available | Medium — single-sourced to Proofpoint |
| Unexpected credential access or email exfiltration from OWA sessions | Exchange mailbox audit logs, DLP alerts | Medium — single-sourced to Proofpoint |
6. Detection
Insufficient indicators to author detection rules. The source material does not contain specific strings, file names, registry keys, mutex names, command-line artefacts, or network indicators associated with OWAReaper. Detection should rely on the behavioural indicators in §5 — anomalous OWA session persistence, unexpected JavaScript execution in the OWA context, and unusual email/credential access patterns — correlated against the March 2026 onward timeframe.
7. Sources
- Recorded Future News / The Record — "Laundry Bear's webmail hackers had more in store after February, report says" — https://therecord.media/russia-hackers-outlook-webmail-malware — 2026-07-29
- Proofpoint (referenced via The Record) — OWAReaper and Laundry Bear OWA campaign research — 2026-07-29 (primary technical source)
8. Adverse Trace position
This is a credible but single-sourced report of a state-linked espionage actor actively targeting OWA infrastructure relevant to EMEA financial services. The "half-click" delivery model and purpose-built JavaScript implant represent a meaningful capability improvement that bypasses traditional email security controls. The vulnerability (CVE-2026-42897) is patched, but the gap between exploitation onset (March 2026) and Microsoft remediation guidance (mid-July 2026) means exposed organisations should assume potential compromise during the window. Attribution to Laundry Bear / TA488 / Void Blizzard is unconfirmed per MITRE ATT&CK data. We assess the risk to unpatched OWA environments as high. We will monitor for Proofpoint's full technical report and any IOC releases, and will update this advisory if corroborating data emerges. Clients with internet-facing OWA should treat patching and log review as immediate priorities.
Published via PulseTrace — Adverse Trace threat intelligence.