The Russian state-sponsored hacking group known as Laundry Bear (also tracked as Void Blizzard and TA488) is carrying out a high-stakes cyber espionage campaign by exploiting a zero-day vulnerability in Microsoft Exchange Server's Outlook Web Access (OWA). Designated CVE-2026-42897, the flaw is a cross-site scripting (XSS) issue that allows arbitrary JavaScript execution in the victim's browser context when a specially crafted email is opened in OWA. What makes this attack particularly dangerous is that it operates as what Proofpoint researchers call a "half-click exploit" — the victim does not need to click any link or download any file. Simply opening the malicious email is enough to trigger the compromise.
The campaign was first detected on July 22, 2026, by email security firm Proofpoint, which has been monitoring the group's activities. Targets include government entities in the United States and Europe, as well as companies in telecommunications, financial services, hospitality, and aerospace sectors. The CVE-2026-42897 vulnerability was originally disclosed by Microsoft on May 14, 2026, with the company warning at the time that the flaw was being actively exploited as a zero-day. However, Proofpoint discovered that Laundry Bear's attack infrastructure for this campaign dates back to March 2026 — two months before Microsoft's advisory — suggesting the group had prolonged access to the vulnerability before any known defenses existed.
The malicious payload delivered by the exploit is a sophisticated backdoor named OWAReaper, described by Proofpoint as the most sophisticated backdoor ever seen delivered via half-click exploits. OWAReaper executes entirely within the Outlook Web Access reading pane. Immediately after execution, the malware uses Outlook APIs to rewrite the email on the Exchange server and remove the exploit content, effectively covering its tracks. Simultaneously, OWAReaper disables OWA pop-ups and right-click functionality during its run, further hindering detection.
What makes OWAReaper particularly alarming is its persistence mechanisms. The backdoor is designed to survive credential rotation — when the victim changes their password, access is not lost — and even complete device re-imaging. This is because the malware's foothold resides within the compromised Exchange mailbox itself, not on the victim's device operating system. OWAReaper establishes two separate command-and-control channels, supports multiple data exfiltration methods, and harvests information including email address, username, and Outlook settings.
This campaign represents a significant evolution in Laundry Bear's capabilities. The group was previously linked to the exploitation of another XSS vulnerability (CVE-2025-66376) as a zero-day in Zimbra email servers, where they delivered a similar JavaScript-based malware called ZimReaper. The transition from Zimbra to Exchange OWA demonstrates considerable technical advancement, as Outlook Web Access represents a more complex and widely deployed target. Proofpoint describes this shift as "a significant improvement in the group's tradecraft and capability."
The broader geopolitical context makes this campaign even more concerning. In recent months, Russia-linked groups have intensified cyber operations on multiple fronts. Beyond Laundry Bear, other Kremlin-sponsored groups like Nobelium (also known as Cozy Bear), responsible for the SolarWinds attack, remain active. Simultaneously, attacks on critical infrastructure such as water treatment facilities, and campaigns by Iran-linked groups, are expanding the global threat landscape.
The emails used in the campaign are described as "banal" by Proofpoint researchers, mimicking supply chain analysis reports, research updates, and performance indicators for tourism and gas markets. The choice of generic, unremarkable themes is intentional — the goal is for the victim to open and read the message but dismiss it as common spam, never suspecting that an exploit has been triggered.
For system administrators and security professionals, the recommendations are clear: immediately apply Microsoft's patch for CVE-2026-42897, implement enhanced monitoring in on-premises Exchange environments, review email folder permissions for suspicious changes, and consider migrating to Exchange Online, which is not affected by this specific vulnerability. Additionally, enabling detailed OWA access logs and implementing behavioral anomaly detection solutions for webmail can help identify malicious activity.
As state-sponsored cyber espionage groups like Laundry Bear continue to refine their tactics, one question remains: if simply opening an email is enough to compromise an entire organization, how can we fundamentally rethink email security in the age of advanced persistent threats?
Sources: BleepingComputer, The Hacker News, The Register
✓ Independent sources cross-checked and verified before publishing