<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae" -->

---
title: Russian hackers expand half-click email attack from...
description: A Russian state-sponsored group (Laundry Bear/Void Blizzard) is exploiting CVE-2026-42897, a zero-day XSS flaw in Microsoft Exchange&#x27;s Outlook Web Access, to...
canonical: https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Russian hackers expand half-click email attack from Zimbra to Microsoft Exchange | daily.dev
og:description: A Russian state-sponsored group (Laundry Bear/Void Blizzard) is exploiting CVE-2026-42897, a zero-day XSS flaw in Microsoft Exchange&#x27;s Outlook Web Access, to...
og:url: https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae
og:image: https://api.daily.dev/og/posts/ge5z3tGAE.png
og:image:alt: Russian hackers expand half-click email attack from Zimbra to Microsoft Exchange
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Russian hackers expand half-click email attack from Zimbra to Microsoft Exchange

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A Russian state-sponsored group (Laundry Bear/Void Blizzard) is exploiting CVE-2026-42897, a zero-day XSS flaw in Microsoft Exchange's Outlook Web Access, to deploy a persistent backdoor called OWAReaper. The attack requires only opening a malicious email in the reading pane — no clicks needed. OWAReaper establishes persistence via mailbox permission escalation (granting Owner-level access to a low-privilege account) and cached email injection via IndexedDB iframes. Critically, this persistence survives password resets and endpoint reimaging, making standard incident response insufficient. C2 uses GitHub commit messages and mailbox emails, with AES-encrypted HTTPS exfiltration through CDN proxies. The campaign is linked to earlier Zimbra attacks using the same half-click technique, now expanded to Exchange. Targeted sectors include government, telecom, finance, hospitality, and aerospace.

## Content

A Russian state-sponsored group tracked as TA488 (also called Laundry Bear or Void Blizzard) has been exploiting a maximum-severity cross-site scripting flaw in Microsoft Exchange's Outlook Web Access to deploy a sophisticated browser-based backdoor called OWAReaper.

The vulnerability, CVE-2026-42897, was patched in July after Microsoft issued mitigation guidance in May. It's already under active exploitation.

## How the attack works

The attack requires only opening a crafted email in OWA — no clicking links, no opening attachments. Proofpoint calls it a "half-click exploit." Once the email is viewed in the reading pane, malicious JavaScript executes in the browser and deploys OWAReaper entirely within the OWA session.

After execution, the implant erases the exploit from the email to cover its tracks, then establishes two persistence mechanisms:

- It grants Owner-level mailbox permissions to a low-privilege default account on the Exchange server
- It injects malicious iframes into cached emails via IndexedDB

The first mechanism is the nastier one. Those server-side permissions survive password resets and full endpoint rebuilds. Standard incident response — rotating credentials, reimaging machines — doesn't remove the attacker's access.

OWAReaper also harvests credentials through browser autofill and can abuse Outlook add-in OAuth tokens to further entrench attacker-controlled accounts.

## Command and control

The backdoor uses two C2 channels: GitHub commit messages and mailbox-delivered emails. Data is exfiltrated via AES-encrypted HTTPS routed through CDN proxies, with DNS-based fallback.

## Targets and context

The campaign has hit US and European government agencies, telecoms, financial institutions, hospitality companies, and aerospace firms.

Proofpoint links TA488 to a parallel campaign exploiting a similar zero-day in Zimbra mail servers, with OWAReaper described as a direct evolution of the ZimReaper malware used in those attacks. The group has essentially ported the technique from Zimbra to Exchange.

Proofpoint describes OWAReaper as the most sophisticated backdoor ever delivered via a half-click exploit.

## What defenders should do

Patch immediately if you haven't. Beyond that, defenders need to treat these compromises as server-side identity incidents rather than endpoint problems. That means correlating mailbox permission changes, add-in activity, and OAuth events — not just running endpoint forensics. Checking for unexpected Owner-level permissions on Exchange mailboxes is a good starting point, since those won't disappear on their own after a credential rotation.

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#malware](https://daily.dev/tags/malware), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Russian hackers expand half-click email attack from Zimbra to Microsoft Exchange","url":"https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae"},"datePublished":"2026-07-30T10:33:46.768Z","dateModified":"2026-07-31T16:10:11.567Z","description":"A Russian state-sponsored group (Laundry Bear/Void Blizzard) is exploiting CVE-2026-42897, a zero-day XSS flaw in Microsoft Exchange's Outlook Web Access, to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a6deb1d040b49c3136ff61113489c687?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a6deb1d040b49c3136ff61113489c687?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/russian-hackers-expand-half-click-email-attack-from-zimbra-to-microsoft-exchange-ge5z3tgae","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,malware,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Russian hackers expand half-click email attack from Zimbra to Microsoft Exchange"}]}
```

