
Laundry Bear Uses “Half-Click” OWA Email Exploit
UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims…
Researchers reported a real TA488 campaign where a specially crafted email exploits an Outlook Web Access (OWA) flaw and runs malicious JavaScript as soon as the user opens the message. The attack relies on normal-looking business topics to get people to quickly view the email, and then uses browser-based persistence so attackers can keep mailbox access even after password resets.
TA488 sent emails with plain, believable business subjects such as supply chain metrics updates, energy market notes, or public health indicators. These topics were chosen because they read as routine and unremarkable, encouraging recipients to open the message quickly in Outlook Web Access without a second thought. Once opened, a vulnerability in OWA allowed embedded JavaScript to execute automatically, meaning the act of opening the email in webmail was enough to trigger the exploit. No link click or attachment download was required.
The campaign succeeded by combining a technical flaw with a social engineering setup that lowered suspicion. Generic, non-urgent subject lines meant the messages did not stand out as threats, so recipients viewed them briefly and moved on rather than reporting them. Because the exploit fired on simply opening the email, normal caution around links or attachments offered no protection. The attackers then used browser-based tooling to attempt to harvest stored Outlook credentials via autofill, extending the impact beyond the initial email.
Organizations should treat routine-looking business emails with the same reporting expectations as obviously suspicious ones, since attackers deliberately design messages to appear harmless. Patch management and configuration hygiene for webmail platforms like OWA are essential, since this attack demonstrates that opening a message can be sufficient for compromise when the underlying service is vulnerable. After any suspected compromise, security teams should not rely on password resets alone; they need to validate that Exchange permissions, OAuth grants, and other persistence mechanisms have been fully removed. Given the range of targeted roles, from executive assistants to operations and IT staff, awareness training should emphasize that anyone using webmail is a potential entry point, not just high-profile executives.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
TA488 sent emails with routine business subjects that, when opened in Outlook Web Access, exploited a vulnerability to automatically execute malicious JavaScript, requiring no additional clicks.
Not necessarily. Attackers changed Exchange mailbox permissions and used OAuth tokens to retain access, so security teams must remove those persistence mechanisms in addition to rotating credentials.
The emails used generic, non-urgent business topics like supply chain metrics or energy markets, which made recipients quickly view them and dismiss them without reporting.
The campaign targeted staff using Outlook Web Access broadly, including executive assistants, operations and supply chain teams, IT/IAM, and security operations personnel.
You open one routine email in Outlook Web Access… and boom, your mailbox is theirs. TA488 abuses an OWA bug, CVE-2026-42897. Just opening their email runs hidden JavaScript in your browser, no link clicks, no attachment, nothing. Their OWAReaper code quietly grabs your stored Outlook credentials, tweaks mailbox permissions, and uses OAuth tokens so they stay in even after you change your password. If a “totally normal” business email in OWA feels even slightly off, don’t just close it, hit the phish report button so security can check for this half-click attack.

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…