Russian spies take their half-click email attack from Zimbra to Outlook

← Back to the feed

Russian spies take their half-click email attack from Zimbra to Outlook

The Register · 3 hours ago

Russian-linked espionage group TA488, also known as Laundry Bear, has reportedly adapted an email-based attack previously used against Zimbra to target on-premises Microsoft Outlook Web Access. Opening a malicious email can trigger attacker-controlled code within an authenticated mail session without requiring the recipient to click a link or download a file, undermining standard phishing precautions; Exchange Online is not affected.

Proofpoint said TA488 exploited CVE-2026-42897, an Outlook Web Access cross-site scripting flaw, against government bodies and firms in sectors including telecommunications, finance, hospitality and aerospace across the US and Europe. The group deploys a mailbox-resident browser implant called OWAReaper, which can persist through password changes and device rebuilds, and may have exploited the flaw from March—around two months before Microsoft’s May patch disclosure.

  • TA488 weaponised Outlook Web Access emails to execute code when messages are opened.
  • The attack affects on-premises Exchange, not Exchange Online.
  • Mailbox-based persistence can survive password resets and rebuilt devices.

Europe World

Read the full article at the source →