
Russian state hackers are utilizing a maximum-severity vulnerability in Microsoft Outlook’s Trade Server to backdoor unpatched machines and steal credentials and different confidential info from them, safety researchers mentioned Thursday.
The assaults are coming from TA488, a monitoring title for a gaggle engaged on behalf of the Kremlin, Proofpoint researchers mentioned Thursday. Proofpoint and the Nationwide Safety Company collectively warned final week that the group, additionally tracked as Laundry Bear and Void Blizzard, had been finishing up related assaults by exploiting a zero-day vulnerability in an e-mail service from Zimbra. The revelation that TA488 can be exploiting the Trade Server vulnerability to put in superior malware when a consumer does nothing aside from open an e-mail despatched to an Outlook Internet Entry (OWA) account has elevated the group’s profile and assessments of its talents.
Doubling down
“TA488 is doubling down on the usage of ‘half-click’ exploits—the place opening the e-mail is sufficient to set off compromise—with considerably improved loading mechanisms, strategies, and malware, signaling an enchancment within the group’s tradecraft and functionality,” Proofpoint researchers wrote. “This novel an infection chain ends with a beforehand unknown JavaScript browser-based implant we name OWAReaper, purpose-built for persistent entry inside OWA.”
The vulnerability, tracked as CVE-2026-42897, is a cross-site-scripting vulnerability, normally abbreviated as XSS, that Microsoft supplied mitigation recommendation for in Could and patched in July. Microsoft gave it a most severity ranking. The vulnerability, which stems from a failure to correctly filter HTML embedded in an e-mail, permits malicious JavaScript execution. Proofpoint mentioned that TA488 might have exploited it as a zero-day.
The malicious JavaScript installs a novel, custom-built browser extension that offers attackers persistent entry to victims’ OWA accounts. Proofpoint mentioned it was probably the most refined backdoor the corporate has ever seen delivered by way of a half-click exploit. The corporate has named it OWAReaper.




