“No-Action” Emails Trigger OWA Mailbox Takeover

The Hacker News · High sophistication
Last updated July 30, 2026

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant designed to keep mailbox access even after password resets or device rebuilds.

How the attack worked

This campaign relied on a “half-click” exploit chain: opening or viewing an email in a vulnerable version of Outlook Web Access (OWA) was enough to trigger compromise, no clicking required beyond reading the message. The emails were deliberately vague, labeled as informational updates with wording like "no action required," and mimicked harmless content such as supply chain analyses, research updates, or tourism and gas market metrics. None of the messages contained links or attachments, which removed the usual visual cues defenders and filters look for.

Once a recipient opened the email in a vulnerable OWA session, the flaw tracked as CVE-2026-42897 delivered a browser-based implant referred to as "OWAReaper." This implant was designed for persistence and mailbox takeover, and it was built to survive normal remediation steps like password resets or reimaging the affected device.

Why it succeeded

The approach succeeded because it removed the traditional "tell" that awareness training focuses on: suspicious links or attachments. By excluding both, the messages felt low-risk and were more likely to be opened and skimmed rather than deleted or reported. The generic, mass-mailing style of the lures also helped the emails blend into ordinary spam rather than stand out as a targeted threat, letting the campaign reach a broad set of organizations across government, telecommunications, financial services, hospitality, and aerospace sectors.

What to watch for

  • Emails that describe themselves as informational and explicitly state no action is required, especially when the topic is vague or irrelevant to your role.
  • Messages from unexpected senders, including previously compromised addresses or unfamiliar external senders, that read like a generic bulletin you never subscribed to.
  • Any unusual mailbox behavior after opening a webmail message, since browser-based implants like this one can persist even after a password change.

How to build resistance

Security teams should reinforce that the absence of links or attachments does not make an email safe, particularly on unpatched webmail platforms. Staff using OWA, government and contractor personnel, and teams in finance, telecommunications, and aerospace should be encouraged to report vague "no action required" emails rather than dismiss them as harmless spam. Incident response processes should also account for server-side persistence, meaning suspected compromises require deliberate removal from the Exchange server rather than relying solely on credential rotation or device rebuilds.

Key findings

  • Threat actors used “half-click” email exploits where viewing the email is enough to trigger compromise in vulnerable webmail.
  • Emails were intentionally vague and “no action required,” avoiding links/attachments to increase the chance recipients would open them.
  • The OWA exploit (CVE-2026-42897) delivered a browser-based implant (“OWAReaper”) designed for persistence and mailbox takeover that can survive credential rotation and device re-imaging.
  • Targets included U.S. and European government entities and organizations in telecommunications, financial, hospitality, and aerospace sectors.
  • Campaign attributed by Proofpoint to Laundry Bear / TA488 (aka CL-STA-1114, UNK_PitStop, Void Blizzard).

Who’s being targeted

  • Commonly targeted roles: All staff using Outlook Web Access (OWA), Government employees and contractors, Defense/Aerospace teams, Finance teams, Telecommunications teams, Executive leadership and executive assistants, IT and Security operations.
  • Affected industries: Government, Telecommunications, Financial services, Hospitality, Aerospace.
  • Attack channels: email.
  • Impersonated: A known/compromised contact or a generic external sender using Proton Mail, Previously compromised email address (internal or partner) sending a harmless-looking bulletin.

Red flags to watch for

  • Vague topic and generic wording that feels like spam but claims to be “informational”
  • Unusual sender origin (e.g., Proton Mail) or a message from an unexpected “known” contact
  • Email contains no links/attachments yet still feels like it’s trying to get you to open it
  • Out-of-context “weekly bulletin” you didn’t subscribe to
  • Sender is a real address but message is oddly generic and doesn’t reference your organization
  • Encourages opening/reading but provides no specific request
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a half-click exploit?

It is an exploit where simply opening or viewing an email in vulnerable webmail is enough to trigger compromise, without the recipient clicking any link or attachment.

Why did these emails have no links or attachments?

Attackers intentionally excluded links and attachments so the message would look harmless and legitimate, increasing the chance the recipient would open and read it, which alone fired the exploit.

Does resetting a password remove the attacker after this exploit?

No. This persistent access lives on the server side, so credential rotation and even full re-imaging of the targeted device will not evict the actor without deliberate removal from the Exchange server.

Who was targeted in this campaign?

Targets included U.S. and European government entities and organizations in telecommunications, financial, hospitality, and aerospace sectors.

Read the video transcript

Imagine an email that hacks your mailbox just because you read it in Outlook Web Access, no links, no attachments. Laundry Bear, also called TA488, is abusing a bug in OWA, CVE-2026-42897. Their "half-click" emails look like boring updates, supply chain research, tourism or gas market metrics, sent from Proton Mail or even a compromised coworker. The second you view it in vulnerable OWA, the exploit fires and drops a browser implant called OWAReaper. It quietly takes over your mailbox and can survive password changes and even a full device rebuild. If you see a vague "no action required" bulletin in OWA that feels out of place, stop and report it to Security, don’t open it in the web browser.

Similar attacks