Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian State-Sponsored Hackers Exploit Exchange OWA Vulnerability for Long-Term Mailbox Access

A sophisticated hacking group linked to the Russian government has been exploiting a previously unknown vulnerability in Microsoft’s Outlook Web Access (OWA) platform to gain long-term access to email accounts of various organizations, including government entities and companies in the telecommunications, financial, hospitality, and aerospace sectors. The hackers, known as Laundry Bear or Void Blizzard, have been using this exploit to deliver a sophisticated backdoor called OWAReaper, which allows them to steal sensitive information and maintain persistence on the compromised systems.

The exploit, identified as CVE-2026-42897, is a cross-site scripting (XSS) vulnerability that enables attackers to execute arbitrary JavaScript in the browser context when users open a specially crafted email in the OWA app. This type of attack is referred to as a “half-click exploit” because victims only need to open the malicious email to trigger the exploited vulnerability. The hackers have been using this method to evade detection and deliver malware that can persist even after system reinstallation or credential rotation.

Laundry Bear’s use of CVE-2026-42897 is particularly noteworthy, as it was first identified by Microsoft in May 2026, just two months before the hacking group began exploiting it. According to research by email security company Proofpoint, the threat actor had created the attack infrastructure for the OWAReaper campaign as early as March 2026. The hackers have been using this exploit to target various organizations, often using topic-specific lures such as supply-chain analyses or research updates to entice victims into opening the malicious emails.

The OWAReaper backdoor is a highly sophisticated piece of malware that allows attackers to collect sensitive information from compromised email accounts, including email addresses, usernames, and Outlook settings. It also attempts to steal access credentials by creating invisible elements in the Document Object Model (DOM) and waiting for the browser to automatically fill them in. Moreover, OWAReaper employs a long-term persistence mechanism that enables hackers to maintain access to the target’s mailbox even if system reinstallation or credential rotation is performed.

The exploit delivers a Base64-encoded payload blob embedded in social media icon URLs after the ‘#’ character, which is then executed by a JavaScript loader. The researchers describe OWAReaper as “the most sophisticated backdoor delivered via half-click exploits” they have seen. Analysis revealed a suite of subtle persistence mechanisms that allow attackers to maintain access to compromised systems.

The implications of this exploit are significant, as it highlights the ongoing threat posed by state-sponsored hacking groups to organizations worldwide. The fact that Laundry Bear was able to exploit a previously unknown vulnerability in OWA and deliver highly sophisticated malware underscores the importance of timely patching and robust security measures.

As a result of this exploit, we recommend that all organizations take immediate action to protect themselves against these types of attacks:

* Ensure that all systems are up-to-date with the latest patches and security updates.

* Implement robust email security controls, including filtering and sandboxing.

* Educate users on the risks associated with half-click exploits and the importance of reporting suspicious emails.

* Regularly review and update access controls to prevent attackers from maintaining persistence.


Source: Bleeping Computer — 2026-07-29