Russian spies take their half-click email attack from Zimbra to Outlook
Russian-linked espionage group TA488, also known as Laundry Bear, has reportedly adapted an email-based attack previously used against Zimbra to target on-premises Microsoft Outlook Web Access. Opening a malicious email can trigger attacker-controlled code within an authenticated mail session without requiring the recipient to click a link or download a file, undermining standard phishing precautions; Exchange Online is not affected.
Proofpoint said TA488 exploited CVE-2026-42897, an Outlook Web Access cross-site scripting flaw, against government bodies and firms in sectors including telecommunications, finance, hospitality and aerospace across the US and Europe. The group deploys a mailbox-resident browser implant called OWAReaper, which can persist through password changes and device rebuilds, and may have exploited the flaw from March—around two months before Microsoft’s May patch disclosure.
- TA488 weaponised Outlook Web Access emails to execute code when messages are opened.
- The attack affects on-premises Exchange, not Exchange Online.
- Mailbox-based persistence can survive password resets and rebuilt devices.