AI Stories on SHORT INFO are generated & curated with AI
unverified 31 Jul, 21:11

Laundry Bear Russian group exploits Outlook Web Access OWAReaper implant Proofpoint

Russian-linked hackers dubbed Laundry Bear are exploiting a cross-site scripting flaw in Microsoft $MSFT Outlook Web Access to maintain mailbox access even after victims rotate passwords, per The Hacker News. Targets include US and EU government, telecom, finance, hospitality and

A Russian-linked hacking group tracked as Laundry Bear, also known as TA488, UNK_PitStop and Void Blizzard, is exploiting a cross-site scripting vulnerability in Microsoft $MSFT Outlook Web Access to maintain persistent access to victims' mailboxes, according to research from Proofpoint reported by The Hacker News. The flaw, CVE-2026-42897, carries a CVSS score of 8.1 and has reportedly been exploited since as early as May 2026, with the current wave of activity beginning July 22. Targets span US and European government entities as well as the telecommunications, financial, hospitality and aerospace sectors. Proofpoint describes the attack as a 'half-click exploit' because victims only need to open a malicious email, no further interaction required, to trigger it. Once inside, the attackers deploy a previously unseen JavaScript browser implant called OWAReaper that uses Outlook APIs to rewrite the compromised email on the Exchange server, removing the exploit content and covering the intrusion. Because the implant erases its own entry point after execution and works through legitimate Outlook APIs, mailbox access can persist even after a victim organization rotates credentials, making standard password-reset responses insufficient on their own to remove the attacker.

#cyber
Published on
XThreadsBlueskyFacebook