Russian hackers target US and European political institutions using XSS vulnerability in Outlook Web Access
OWAReaper doesn’t lock or destroy your files, but rather spies on you.

Image by Cybernews.
- Russian threat group TA488 exploits Outlook XSS vulnerability requiring only opening an email to compromise targets.
- OWAReaper backdoor steals authentication tokens, reads emails, and maintains long-term access without passwords needed.
- Campaign targets US and European government, telecommunications, finance, hospitality, and aerospace sectors since July 2026.
- Microsoft patched the CVE-2026-42897 vulnerability in June after warning about the issue in May.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Russia-aligned threat actor TA488, also known as Void Blizzard or Laundry Bear, recently launched a campaign against US and European government entities.
According to cybersecurity firm Proofpoint, the attackers abused a vulnerability dubbed CVE-2026-42897. This is a cross-site scripting (XSS) vulnerability in Outlook Web Access, where Outlook Exchange Server doesn’t correctly handle the HTML content of emails.
An XSS attack is one in which malicious code is injected into a trusted website, causing the target to view content from a malicious site.
This allows attackers to gain access to session tokens, passwords, and other sensitive information stored by a web browser. Attackers can also use this method to spread malware or steal user data.
In the malicious campaign, the Russian hackers used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail, targeting entities in the government, telecommunications, finance, hospitality, and aerospace sectors.
In an attempt to avoid scrutiny and hide their origins and motives, the attackers augmented the volume of messages and the scope of their victims to intentionally blend in with mass-mailing spam campaigns.
The attackers used a so-called “half-click exploit,” meaning that just opening an email is enough to compromise a target’s device.
Check if your data has been leaked
“If the email is opened in Outlook Webmail, the Outlook Exchange server mishandles the HTML from the message and runs arbitrary JavaScript. This executes the payload in the message body, an implant Proofpoint calls OWAReaper,” the cybersecurity firm explains.
Security researchers say OWAReaper is the most sophisticated backdoor delivered via half-click exploits that they have ever observed.
On top of that, OWAReaper steals authentication tokens to access Outlook Webmail without knowing the password, reads and steals emails from the victim’s mailbox, collects mailbox information, such as contacts, to see who the target is mailing with, and maintains long-term access.
In a nutshell, OWAReaper is a spying tool designed to gain long-term access to a victim’s Outlook Webmail account.
The infrastructure to make this campaign possible was created in March 2026, Proofpoint states. Two months later, in May 2026, Microsoft warned about the XSS issue. In June, the Redmond-based tech company released an Exchange Server security update that fixed the problem.
Threat researchers didn’t observe any activity of the Russian hackers between February 2026 and July 22nd, 2026. That day, the attackers started abusing the XSS vulnerability in Outlook Web Access.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.