BIP America

collapse
Home / Daily News Analysis / Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Aug 03, 2026  Twila Rosenbaum  7 views
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Russia-affiliated espionage group Laundry Bear, also tracked as Void Blizzard and TA488, is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to attack US and European government entities and a range of private sector organizations. The attack chain begins with a simple email; when the target opens it in Outlook Web Access, the exploit fires and installs a backdoor called OWAReaper.

Security researchers who spotted the campaign say the malicious emails were designed to look so ordinary that recipients would open them, decide they were junk, and move on without reporting them. The messages contained no suspicious links and no malicious attachments, which lowers the chance of being caught by automated email filters and raises the chance that human recipients will ignore the warning signs.

Key facts at a glance

  • Threat actor: Russia-affiliated Laundry Bear, also known as Void Blizzard and TA488.
  • Vulnerability: CVE-2026-42897, a cross-site scripting flaw in Microsoft Exchange webmail.
  • Targets: US and European government entities, plus private sector organizations.
  • Payload: OWAReaper backdoor.
  • Trigger: Opening an email in the Outlook Web Access reading pane.
  • First campaign infrastructure: March 2026.
  • Patch timeline: Temporary mitigation in May 2026; definitive fix in June 2026.

Targeting and lure details

The choice of Microsoft Exchange is significant. Email servers hold some of the most sensitive information in any organization, and webmail interfaces expand the attack surface beyond the traditional email client. Because OWA is accessed through a browser, malicious code can run with the user's session and interact with the mailbox in ways that bypass many endpoint protections.

According to the researchers, the subject lines and lures are deliberately banal, likely so the targeted user opens and skims the message, but dismisses it as junk without reporting it. That is especially important because there are no suspicious URLs or attachments present. The malicious activity is hidden in the structure of the HTML message body, which means traditional email security tools that focus on attachments and links may not flag the message. This approach also lowers the chance that a worried user will forward the email to an IT security team.

Anatomy of the infection

The vulnerability affects the webmail interface for Exchange. The exploit constructs a JavaScript loader from payload blobs stored in the HTML body of the email itself. That loader then delivers OWAReaper, a backdoor that executes in the reading pane of Outlook Web Access. Because the payload is assembled inside the message and runs in the browser, it can evade detection by security tools that inspect files and attachments rather than the behavior of the webmail page.

Once OWAReaper runs, it starts by rewriting the original email on the server to erase the exploit code. It also disables pop-ups and right-clicking while it is active, reducing the likelihood that the user will notice unusual browser behavior or interact with the webmail interface in a way that disrupts the infection.

What OWAReaper does after execution

  • It gathers the target's email address, username, and Outlook settings, then attempts to capture login credentials by injecting invisible form fields into the webmail page.
  • It writes an encrypted copy of itself and a decryption wrapper into the browser's storage area. OWA automatically reads and executes that stored payload when a new OWA tab is opened, so the malware relaunches every time the user starts a fresh session.
  • It checks for Outlook add-ins that have ReadWriteMailbox permissions. If it finds any, it can steal OAuth tokens and grant Owner-level permissions to the 'Default' user on every mail folder. This gives any authenticated user in the same organization full access to the target's mailbox.
  • It adds a hidden iframe to messages stored in OWA's offline IndexedDB message cache and enables caching, which can reinfect re-imaged hosts if the victim opens a poisoned email from the local cache.

The combination of browser storage persistence, hidden iframe reinfection, and server-side permission changes makes OWAReaper unusually difficult to remove. Even if the user's machine is wiped and rebuilt, the attacker may still hold mailbox-level permissions that can be used to re-infect the account once the browser returns to OWA. The backdoor is designed to re-establish itself from multiple angles rather than relying on a single file or process.

Persistence and server-side access

The mailbox infection is not limited to the user's browser. According to the researchers, this is a key aspect of the infection chain: if the threat actor has access to other accounts in the organization, the group maintains persistent access to the target's mailbox. That access lives on the server side and requires deliberate removal from the Exchange server. Credential rotation and even full re-imaging of the targeted user's device will not evict the actor.

Command and control and data theft

OWAReaper is remotely controlled. It can receive commands by fetching public code repository commit messages or by reading specially crafted inbound emails sent by the attacker. This gives the group a flexible command channel that blends in with legitimate internet traffic and email activity. Data stolen from the mailbox can be exfiltrated over HTTPS or through DNS queries, making detection difficult for organizations that do not monitor those channels closely.

Evolution of the payload

OWAReaper is an evolution of the ZimReaper payload, which the same threat actor used in a 2025 campaign that exploited an unknown vulnerability in Zimbra mailservers. The two payloads share code, behavior, and similar error-handling and reporting mechanisms. This suggests the group is actively iterating on tools that work well against webmail platforms and reusing its investment across different targets. The shift from Zimbra to Microsoft Exchange also shows that Laundry Bear is willing to adapt its arsenal to the environments used by the organizations it chooses to attack.

Patch timeline and zero-day likelihood

Microsoft warned about CVE-2026-42897 exploitation in May 2026, when it provided a temporary mitigation. The company then provided a definitive fix in June 2026. The first infrastructure related to this campaign was created in March 202


Source: Help Net Security News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy