TA488 Uses “Half-Click” OWA Emails to Persist

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens an email in the reading pane. The attack uses a cross-site scripting flaw to run hidden JavaScript, install a browser-resident implant, and create server-side mailbox access that can survive password resets and even device re-imaging.

How the Attack Worked

TA488, also tracked as Void Blizzard or Laundry Bear, resumed activity after a period of dormancy with a campaign targeting organizations that rely on on-premises Outlook Web Access. The emails exploited a cross-site scripting flaw, CVE-2026-42897, affecting on-premises Exchange Server rather than Exchange Online. Opening the email in a vulnerable OWA client caused the victim's browser to execute embedded JavaScript within their authenticated session, meaning no link click or attachment download was required to trigger compromise.

Once active, the implant, known as OWAReaper, lived inside the OWA reading pane. It hid itself in browser localStorage under a legitimate-looking settings key and used offline cache and IndexedDB tricks to re-infect sessions. Commanding relied on GitHub commit messages and inbound email polling, while exfiltration used HTTPS through legitimate image CDNs, with DNS tunneling available as a fallback.

Why It Succeeded

The lures were deliberately unremarkable, using ordinary business topics such as semiconductor supply chains, gas markets, and tourism metrics. This banality was likely intentional: recipients opened and skimmed the message, then dismissed it as junk without reporting it, since there were no suspicious links or attachments to flag. Because the exploit fired simply from opening the email in a vulnerable OWA client, standard user caution around links and attachments offered no protection.

The most durable part of the attack was server-side. It granted Exchange's low-privilege Default user Owner-level permissions on every mail folder, effectively opening the mailbox to any authenticated account in the organization. Because this permission grant lived on the server and required deliberate removal from Exchange, credential rotation and device re-imaging did not evict the actor.

What to Watch For

  • Unexpected, low-urgency "business update" emails that encourage skimming rather than action
  • Emails opened in on-premises OWA where reading-pane rendering could be exploited if systems are unpatched
  • Unexplained changes to mailbox folder permissions, particularly involving Default user access grants
  • Unusual outbound traffic to image CDNs or DNS tunneling activity following email access

Building Resistance

Organizations should train employees to report suspicious or irrelevant emails even when no links or attachments are present, since boring-looking messages can still carry risk. IT and security teams should prioritize patching on-premises Exchange and OWA systems, since simply opening an email in webmail can trigger compromise on unpatched deployments. Security operations teams should also conduct regular audits of Exchange mailbox folder permissions, since server-side persistence mechanisms can survive password resets and re-imaging, requiring deliberate removal at the Exchange configuration level rather than relying on credential changes alone.

Key findings

  • TA488 (aka Void Blizzard / Laundry Bear) resumed activity on July 22 after not being seen since February.
  • Attack emails exploited an on‑prem Exchange/OWA cross-site scripting flaw (CVE-2026-42897) so JavaScript executed when the email was opened in OWA, no link or attachment required.
  • Lures were intentionally “unremarkable,” using business topics like semiconductor supply chains, gas markets, and tourism metrics to reduce suspicion and reporting.
  • The implant (OWAReaper) lived in the OWA reading pane, hid itself in browser localStorage under a legitimate settings key, and used offline cache/IndexedDB tricks to re-infect.
  • A server-side persistence step granted broad mailbox folder permissions (via Default user permission changes), meaning credential rotation and re-imaging did not remove access.
  • Commanding used GitHub commit messages and inbound email polling; exfiltration used HTTPS via legitimate image CDNs with DNS tunneling as fallback.

Who’s being targeted

  • Commonly targeted roles: All employees who use OWA/webmail, Executives and senior leaders, Government staff, Finance teams, IT/Exchange administrators, Security operations.
  • Affected industries: Government, Telecommunications, Financial Services, Hospitality, Aerospace.
  • Attack channels: email.
  • Impersonated: Generic external business sender (unspecified/ordinary contact).

Red flags to watch for

  • Unexpected, irrelevant “business update” email that encourages skimming rather than action
  • User did not subscribe/request the content but it looks plausible and non-urgent
  • Email is opened in webmail (OWA) where preview/reading-pane rendering can be abused if unpatched
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Did the victim need to click a link for TA488's attack to work?

No. Simply opening the email in a vulnerable on-premises OWA client caused the browser to execute embedded JavaScript within the victim's authenticated session, with no link or attachment needed.

Does resetting passwords remove TA488's access?

No. The attack granted server-side mailbox folder permissions through Exchange's Default user permission settings, so credential rotation and device re-imaging did not remove the intruder's access.

Which systems were vulnerable to this attack?

The campaign exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server and Outlook Web Access, not Exchange Online.

Why were the phishing emails hard to detect?

The lures used deliberately boring, plausible business topics like semiconductor supply chains, gas markets, and tourism metrics, so recipients skimmed and dismissed them as junk rather than reporting them.

Read the video transcript

Imagine this: you just preview an Outlook Web Access email about tourism metrics… and that alone compromises your mailbox. That’s TA488 abusing a cross‑site scripting bug in on‑prem OWA, CVE‑2026‑42897. No link, no attachment, just opening the email runs hidden JavaScript, drops an implant called OWAReaper into your browser, and quietly gives broad mailbox access on the server. Their trick is banality: subjects about semiconductor supply chains, gas markets, tourism metrics, stuff you skim and forget. But once OWAReaper lives in your reading pane and mailbox permissions are changed, even password resets and device re‑imaging won’t kick them out. If you get a random, irrelevant market or metrics email in OWA, no matter how boring, don’t just close it. Hit the Phish Report button or forward it to security so we can patch, check mailbox permissions, and shut this down.

Similar attacks

“Half-Click” OWA Email Trap Spreads

“Half-Click” OWA Email Trap Spreads

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access…

July 30, 2026