
TA488 Uses “Half-Click” OWA Emails to Persist
Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens…
A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or attachment needed). The implant (“OWAReaper”) can quietly change server-side mailbox permissions and abuse OAuth tokens, so attackers can keep access even after a password reset or device rebuild.
The TA488 group, also tracked as Void Blizzard or Laundry Bear, sent emails crafted to look like routine informational updates, including content about supply chains and market indicators. The key detail is that a recipient did not need to click a link or open an attachment. Simply viewing the message in Outlook Web Access was enough for embedded JavaScript to execute inside the browser's reading pane.
Once triggered, the code launched OWAReaper, a previously undocumented JavaScript implant. The implant runs inside the OWA reading pane, removes the exploit code from the stored message after execution, and can attempt to capture credentials through browser autofill. If a vulnerable Outlook add-in with ReadWriteMailbox permissions is present, OWAReaper can use it to obtain an OAuth token and modify mailbox permissions, creating durable, server-side access.
This attack succeeded because it removed the usual behavioral cues that awareness training focuses on: a suspicious link or an unexpected attachment. Since simply opening the message in OWA was sufficient, the interaction looked like normal email use. The bland, plausible content, styled as generic informational updates, gave recipients no obvious reason for suspicion.
The persistence mechanism also undermines standard incident response assumptions. Because mailbox permissions are stored server-side on Exchange, changing a victim's password or rebuilding their device does not remove attacker access. This means traditional response steps, such as resetting credentials and reimaging endpoints, may not be sufficient on their own.
Organizations should treat
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is an exploit where simply viewing a crafted email in Outlook Web Access triggers malicious JavaScript, with no link click or attachment needed to execute the code.
OWAReaper can modify mailbox permissions stored on the Exchange server itself, so resetting a password or rebuilding the endpoint does not remove that server-side access.
TA488, also known as Void Blizzard or Laundry Bear, targeted government and multiple commercial sectors including telecommunications, financial services, hospitality, and aerospace.
Responders should review mailbox permission changes, add-in activity, and OAuth token events for users who opened suspicious OWA messages, not just reset passwords and reimage devices.
Imagine this: you just preview an email in Outlook Web Access, and that alone hands over your mailbox. Russia‑aligned TA488 used a “half‑click” exploit in OWA: their email runs OWAReaper JavaScript just by being viewed in the reading pane, no link, no attachment, no click. OWAReaper can grab autofilled credentials, abuse an Outlook add‑in to get an OAuth token, then quietly change mailbox permissions so they keep access even after password resets or device rebuilds. Here’s the move: if an unexpected “routine update” email in OWA feels off, even with no links or attachments, report it, so security can check mailbox permissions and OAuth activity behind the scenes.

Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens…

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims…