Half-Click OWA Emails Trigger Stealth Mailbox Takeover

CSO Online · High sophistication
Last updated July 30, 2026

A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or attachment needed). The implant (“OWAReaper”) can quietly change server-side mailbox permissions and abuse OAuth tokens, so attackers can keep access even after a password reset or device rebuild.

How the attack worked

The TA488 group, also tracked as Void Blizzard or Laundry Bear, sent emails crafted to look like routine informational updates, including content about supply chains and market indicators. The key detail is that a recipient did not need to click a link or open an attachment. Simply viewing the message in Outlook Web Access was enough for embedded JavaScript to execute inside the browser's reading pane.

Once triggered, the code launched OWAReaper, a previously undocumented JavaScript implant. The implant runs inside the OWA reading pane, removes the exploit code from the stored message after execution, and can attempt to capture credentials through browser autofill. If a vulnerable Outlook add-in with ReadWriteMailbox permissions is present, OWAReaper can use it to obtain an OAuth token and modify mailbox permissions, creating durable, server-side access.

Why it succeeded

This attack succeeded because it removed the usual behavioral cues that awareness training focuses on: a suspicious link or an unexpected attachment. Since simply opening the message in OWA was sufficient, the interaction looked like normal email use. The bland, plausible content, styled as generic informational updates, gave recipients no obvious reason for suspicion.

The persistence mechanism also undermines standard incident response assumptions. Because mailbox permissions are stored server-side on Exchange, changing a victim's password or rebuilding their device does not remove attacker access. This means traditional response steps, such as resetting credentials and reimaging endpoints, may not be sufficient on their own.

What to watch for

  • Unexpected messages framed as routine updates, such as supply chain or market briefs, with no clear reason for being sent
  • No requirement to click a link or open an attachment for compromise to occur
  • Unexplained mailbox permission changes following a suspicious email being opened
  • Unusual OAuth token grants or Outlook add-in activity tied to a mailbox

Building resistance

Organizations should treat

Key findings

  • TA488 (aka Void Blizzard / Laundry Bear) targeted government and multiple commercial sectors using crafted emails viewed in Outlook Web Access (OWA).
  • The exploit is described as “half-click”: victims do not need to click a link or open an attachment, viewing the email in OWA is enough to execute JavaScript.
  • The OWAReaper JavaScript implant runs in the OWA reading pane, removes exploit code from the stored message after execution, and can attempt to capture credentials via browser autofill.
  • If a suitable Outlook add-in is present, the implant can obtain an OAuth token and modify mailbox permissions to create durable server-side access.
  • Because persistence is stored on the Exchange server (mailbox permissions), password changes and endpoint rebuilds may not remove attacker access.
  • Traditional endpoint- and email-focused security controls may miss the activity due to lack of attachments/links and because actions can resemble normal mailbox behavior.

Who’s being targeted

  • Commonly targeted roles: All employees who use Outlook Web Access (OWA), Government users, Executives, Operations and supply chain teams, IT/Exchange administrators, Security operations / incident response.
  • Affected industries: Government, Telecommunications, Financial services, Hospitality, Aerospace.
  • Attack channels: email.
  • Impersonated: Generic newsletter/industry update sender (not specified).

Red flags to watch for

  • Vague content that looks like a routine update but comes unexpectedly
  • No clear reason you were targeted or subscribed
  • Using OWA/reading pane is enough to trigger the attack (no link/attachment needed)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a half-click OWA attack?

It is an exploit where simply viewing a crafted email in Outlook Web Access triggers malicious JavaScript, with no link click or attachment needed to execute the code.

How does OWAReaper maintain access after a password reset?

OWAReaper can modify mailbox permissions stored on the Exchange server itself, so resetting a password or rebuilding the endpoint does not remove that server-side access.

Which groups or sectors were targeted by this attack?

TA488, also known as Void Blizzard or Laundry Bear, targeted government and multiple commercial sectors including telecommunications, financial services, hospitality, and aerospace.

What should incident responders check if OWAReaper is suspected?

Responders should review mailbox permission changes, add-in activity, and OAuth token events for users who opened suspicious OWA messages, not just reset passwords and reimage devices.

Read the video transcript

Imagine this: you just preview an email in Outlook Web Access, and that alone hands over your mailbox. Russia‑aligned TA488 used a “half‑click” exploit in OWA: their email runs OWAReaper JavaScript just by being viewed in the reading pane, no link, no attachment, no click. OWAReaper can grab autofilled credentials, abuse an Outlook add‑in to get an OAuth token, then quietly change mailbox permissions so they keep access even after password resets or device rebuilds. Here’s the move: if an unexpected “routine update” email in OWA feels off, even with no links or attachments, report it, so security can check mailbox permissions and OAuth activity behind the scenes.

Similar attacks