
Zimbra Zero-Day Email: Preview Triggers Espionage
A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…
UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims simply by being opened in Outlook Web Access. The email’s HTML triggers the server to run attacker code, installing a mailbox-stealing backdoor (“OWAReaper”) that can persist and reinfect even after device re-imaging. Targeting was unusually broad across multiple sectors, likely to blend in with normal spam traffic.
The group tracked as Laundry Bear (TA488) sent emails from a series of compromised accounts, exploiting a vulnerability in Outlook Webmail. Simply opening the message in Outlook Web Access was enough: the Outlook Exchange server mishandled the HTML content of the message and executed arbitrary JavaScript. This is what researchers describe as a half-click technique, since it requires no link click, no attachment open, and no additional user interaction beyond viewing the email. That JavaScript executed a payload called OWAReaper, an implant built to maintain long-term access to a victim's mailbox.
Several factors made this campaign effective. First, targeting was unusually broad across government, telecommunications, finance, hospitality, and aerospace organizations, which likely helped the malicious emails blend into normal mass-mailing spam traffic rather than standing out as a targeted lure. Second, the messages came from compromised accounts rather than spoofed or unfamiliar senders, making them appear more legitimate to recipients who trust known contacts. Third, the core mechanism relies on a webmail vulnerability rather than user judgment, so the usual advice of avoiding suspicious links or attachments does not fully protect against it.
Because OWAReaper can persist through a hidden iframe stored in OWA's offline IndexedDB message cache, reopening an older poisoned email can reinfect a mailbox even after cleanup efforts. Security teams should treat repeated post-remediation symptoms as a signal to investigate the mailbox and webmail layer itself, not just the endpoint device. Employees across all roles that use Outlook Web Access, including executives, finance staff, IT administrators, and general staff, should be encouraged to report anything unusual seen in webmail, even if they did not click on anything. Given the attack requires no interaction beyond opening a message, timely patching of the underlying webmail vulnerability and rapid incident response escalation are central to limiting exposure, alongside awareness that a compromised colleague account can be the source of a malicious email.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a technique where opening an email in Outlook Webmail is enough to trigger malicious JavaScript execution, without the victim clicking any link or attachment.
OWAReaper is described as a highly sophisticated implant designed to maintain access to mailboxes, and it can persist even after credential rotation and full device re-imaging.
OWAReaper can reinfect a device through a hidden iframe stored in OWA's offline IndexedDB message cache, so reopening an older poisoned email can trigger the exploit again.
Targeting was unusually broad across government, telecommunications, finance, hospitality, and aerospace sectors, likely to blend in with normal spam traffic.
You know that feeling of safety, "I just opened the email, I didn’t click anything"? Laundry Bear just blew that up. Russian-linked Laundry Bear, TA488, used a bug in Outlook Web Access, CVE-2026-42897, so that just opening their email in webmail runs their JavaScript on the server and drops a mailbox backdoor called OWAReaper. Their trick: they hijack real accounts to send broad, spammy-looking messages. You open one in OWA, OWAReaper lands in your mailbox, and it can even hide in cached emails so reopening an old message later silently reinfects you, yes, even after a laptop rebuild. If your mailbox keeps acting weird, repeated logins, strange sends, issues even after password resets or rebuilds, stop assuming it’s your laptop. Report it to security immediately and say, "This might be an OWA webmail issue."

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP…

Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live…

Researchers reported a real TA488 campaign where a specially crafted email exploits an Outlook Web Access (OWA) flaw and runs malicious JavaScript as soon as…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…