AI & TechBigTech CompaniesCybersecurityNewswireTechnology

Kremlin hackers actively exploit critical Exchange server flaw

Originally published on: July 31, 2026
▼ Summary

– Russian state hackers from TA488 are exploiting a maximum-severity XSS vulnerability in Microsoft Outlook Exchange Server, tracked as CVE-2026-42897, to backdoor unpatched machines and steal credentials.
– The attacks use “half-click” exploits where merely opening an email in Outlook Web Access triggers compromise, without requiring further user action.
– Proofpoint researchers identified a novel JavaScript browser implant called OWAReaper that provides persistent access to victims’ OWA accounts.
– TA488, also known as Laundry Bear and Void Blizzard, previously exploited a zero-day in Zimbra email service, and their latest attacks show improved tradecraft.
– Microsoft provided mitigation advice for the vulnerability in May and patched it in July, but Proofpoint suggests TA488 may have exploited it as a zero-day before the patch.

Russian state-sponsored hackers are actively exploiting a critical Microsoft Outlook Exchange Server vulnerability to plant backdoors on unpatched systems and siphon credentials with other sensitive data, cybersecurity researchers disclosed Thursday.

The attacks are being orchestrated by TA488, a threat group linked to the Kremlin, according to a report from Proofpoint. Just last week, Proofpoint and the National Security Agency issued a joint warning that the same group,also known as Laundry Bear and Void Blizzard,had been leveraging a zero-day flaw in Zimbra’s email platform. Now, evidence shows TA488 is also weaponizing a maximum-severity Exchange Server bug to deploy advanced malware. The infection triggers simply when a user opens an email sent to an Outlook Web Access (OWA) account, a method that has sharply raised the group’s threat profile and perceived technical prowess.

“TA488 is doubling down on the use of ‘half-click’ exploits,where opening the email is enough to trigger compromise,with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability,” Proofpoint researchers wrote. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.”

The exploited vulnerability, designated CVE-2026-42897, is a cross-site scripting (XSS) flaw. Microsoft issued mitigation guidance in May and released a patch in July, assigning it the highest possible severity rating. The bug originates from a failure to properly sanitize HTML embedded in email messages, allowing malicious JavaScript to execute. Proofpoint noted that TA488 may have used this vulnerability as a zero-day before the patch was available.

The injected JavaScript installs a custom-built browser extension, granting attackers persistent access to victims’ OWA accounts. Proofpoint described OWAReaper as the most sophisticated backdoor the company has ever observed delivered through a half-click exploit.

(Source: Ars Technica)

Topics

state-sponsored hacking 98% exchange server vulnerability 97% zero-day exploitation 93% owareaper implant 92% kremlin-linked groups 91% half-click exploits 90% credential theft 89% advanced malware deployment 88% persistent access 87% cross-site scripting (xss) 86%