
Half-Click OWA Emails Trigger Stealth Mailbox Takeover
A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or…
Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens an email in the reading pane. The attack uses a cross-site scripting flaw to run hidden JavaScript, install a browser-resident implant, and create server-side mailbox access that can survive password resets and even device re-imaging.
TA488, also tracked as Void Blizzard or Laundry Bear, resumed activity after a period of dormancy with a campaign targeting organizations that rely on on-premises Outlook Web Access. The emails exploited a cross-site scripting flaw, CVE-2026-42897, affecting on-premises Exchange Server rather than Exchange Online. Opening the email in a vulnerable OWA client caused the victim's browser to execute embedded JavaScript within their authenticated session, meaning no link click or attachment download was required to trigger compromise.
Once active, the implant, known as OWAReaper, lived inside the OWA reading pane. It hid itself in browser localStorage under a legitimate-looking settings key and used offline cache and IndexedDB tricks to re-infect sessions. Commanding relied on GitHub commit messages and inbound email polling, while exfiltration used HTTPS through legitimate image CDNs, with DNS tunneling available as a fallback.
The lures were deliberately unremarkable, using ordinary business topics such as semiconductor supply chains, gas markets, and tourism metrics. This banality was likely intentional: recipients opened and skimmed the message, then dismissed it as junk without reporting it, since there were no suspicious links or attachments to flag. Because the exploit fired simply from opening the email in a vulnerable OWA client, standard user caution around links and attachments offered no protection.
The most durable part of the attack was server-side. It granted Exchange's low-privilege Default user Owner-level permissions on every mail folder, effectively opening the mailbox to any authenticated account in the organization. Because this permission grant lived on the server and required deliberate removal from Exchange, credential rotation and device re-imaging did not evict the actor.
Organizations should train employees to report suspicious or irrelevant emails even when no links or attachments are present, since boring-looking messages can still carry risk. IT and security teams should prioritize patching on-premises Exchange and OWA systems, since simply opening an email in webmail can trigger compromise on unpatched deployments. Security operations teams should also conduct regular audits of Exchange mailbox folder permissions, since server-side persistence mechanisms can survive password resets and re-imaging, requiring deliberate removal at the Exchange configuration level rather than relying on credential changes alone.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
No. Simply opening the email in a vulnerable on-premises OWA client caused the browser to execute embedded JavaScript within the victim's authenticated session, with no link or attachment needed.
No. The attack granted server-side mailbox folder permissions through Exchange's Default user permission settings, so credential rotation and device re-imaging did not remove the intruder's access.
The campaign exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server and Outlook Web Access, not Exchange Online.
The lures used deliberately boring, plausible business topics like semiconductor supply chains, gas markets, and tourism metrics, so recipients skimmed and dismissed them as junk rather than reporting them.
Imagine this: you just preview an Outlook Web Access email about tourism metrics… and that alone compromises your mailbox. That’s TA488 abusing a cross‑site scripting bug in on‑prem OWA, CVE‑2026‑42897. No link, no attachment, just opening the email runs hidden JavaScript, drops an implant called OWAReaper into your browser, and quietly gives broad mailbox access on the server. Their trick is banality: subjects about semiconductor supply chains, gas markets, tourism metrics, stuff you skim and forget. But once OWAReaper lives in your reading pane and mailbox permissions are changed, even password resets and device re‑imaging won’t kick them out. If you get a random, irrelevant market or metrics email in OWA, no matter how boring, don’t just close it. Hit the Phish Report button or forward it to security so we can patch, check mailbox permissions, and shut this down.

A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access…

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…