Russian Hackers Exploit Webmail Zero-Days To Steal Mailboxes

Security researchers have exposed a sustained espionage campaign in which the Russian state-sponsored hacking group known as Laundry Bear, also tracked as Void Blizzard or TA488, exploited zero-day vulnerabilities in two of the world's most widely deployed webmail platforms, Microsoft Exchange Outlook Web Access (OWA) and Zimbra Collaboration Suite.

The group used these flaws to install sophisticated backdoors that steal emails, credentials, and multi-factor authentication codes, and that in some cases survive password resets and full system reimaging.

Russian Hackers Exploit Webmail Zero-Days To Steal Mailboxes

Proofpoint researchers first documented the Zimbra intrusion and then, months later, identified a related, more advanced campaign targeting only Exchange OWA users. Microsoft separately confirmed active exploitation of the Exchange flaw and released emergency mitigations while it prepared a permanent fix.

Proofpoint discovered the Exchange campaign roughly a week before publishing its findings and traced it to organizations across the United States and Europe, including government agencies and companies in telecommunications, finance, hospitality, and aerospace. The attackers exploited CVE-2026-42897, a cross-site scripting flaw that allows an attacker to run arbitrary JavaScript in a victim's browser by getting them to open a specially crafted email in OWA.

Microsoft disclosed CVE-2026-42897 on May 14, 2026, describing it as a spoofing vulnerability rooted in improper neutralization of input during web page generation. The flaw affects fully patched on-premises deployments of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition, but not Exchange Online. Proofpoint's telemetry shows Laundry Bear built its attack infrastructure for this campaign in March, roughly two months before Microsoft issued its advisory, meaning the group operated with a genuine zero-day for an extended period.

Proofpoint calls this style of attack a "half-click exploit" because a victim only needs to open the malicious message for the code to run; no link click or attachment download is required. The group deliberately wrote bland, work-related subject lines covering topics such as supply-chain analysis and tourism or gas-market indicators, so that targets skim and dismiss the emails as unimportant rather than reporting them as suspicious. Because the messages carry no suspicious links or attachments, they raise fewer red flags for both users and automated filters.

The exploit itself relies on Exchange's failure to properly sanitize HTML in the message body. Proofpoint found that the attackers embedded a JavaScript loader and Base64-encoded payload fragments inside social media icon URLs, positioned after the "#" character so that standard sanitization routines pass them through unnoticed.

The payload delivered through this exploit chain, which Proofpoint named OWAReaper, represents what the company describes as the most sophisticated backdoor it has observed delivered through a half-click exploit. Researchers assess it as a direct evolution of ZimReaper, the malware family that the same actor used against Zimbra servers.

OWAReaper executes entirely within the OWA reading pane. Once active, it uses Outlook APIs to rewrite the malicious email directly on the Exchange server, stripping out the exploit code to erase evidence of the intrusion. At the same time, it disables browser pop-ups and right-click functionality within OWA to reduce the chance a user notices anything unusual.

The malware harvests the compromised account's email address, username, and Outlook configuration settings, and it attempts to capture login credentials by planting invisible form fields in the page's Document Object Model and waiting for the browser's autofill feature to populate them.

Persistence That Survives Password Resets

The most alarming capability Proofpoint documented is OWAReaper's ability to retain mailbox access even after a compromised system is wiped and reimaged, or the user's password is changed. The malware scans for installed Outlook add-ins that hold ReadWriteMailbox permissions and abuses the GetClientAccessToken operation to steal OAuth access tokens through those add-ins.

It then calls the UpdateFolder function to grant Owner-level permissions on every mail folder to the "Default" account, a low-privilege alias present in every Exchange tenant. Because this permission change lives on the Exchange server rather than on the victim's device, resetting credentials or restoring the machine from a clean image does not revoke it, and any authenticated account within the organization can subsequently read the mailbox.

A second persistence mechanism reinforces the first. OWAReaper enables local caching and injects a malicious iframe into the HTML of messages stored in OWA's offline IndexedDB, so the exploit re-executes automatically every time the victim reopens the poisoned message from the cache, even without a network connection to the original malicious sender.

Proofpoint found that OWAReaper builds in redundancy at every stage of its operation, likely to keep functioning if any single channel is discovered and blocked. The malware supports two separate methods for both command delivery and data theft:

  • For commands, it queries GitHub's Commit Search API every 24 hours for encrypted messages matching a specific format tied to the victim's email address, and it can also scan incoming emails in the IndexedDB cache for messages structured as an email address followed by a Base64-encoded string.
  • For exfiltration, it primarily sends data over HTTPS using AES-CTR encrypted URI paths proxied through legitimate image content-delivery network domains; if that channel fails, it falls back to sending data directly to an attacker-controlled server, and ultimately to a DNS-based exfiltration method that encodes stolen data using Base32.

Proofpoint attributed the campaign to TA488 based on behavioral overlaps with the earlier Zimbra intrusions and published a limited set of indicators of compromise, including malicious domains and the exploit's HTML structure.

The Exchange operation follows a nearly identical campaign against Zimbra Collaboration Suite that the same actor ran for months beforehand. CISA and Proofpoint reported that Laundry Bear exploited CVE-2025-66376, a stored cross-site scripting flaw in Zimbra's Classic UI, as a zero-day before the company patched it in November 2025, and continued targeting servers that remained unpatched afterward. As with the Exchange flaw, victims needed only to view a malicious HTML email for the embedded JavaScript to execute automatically.

That campaign delivered ZimReaper, which harvested a victim's most recent 90 days of email, their address book, browser-stored passwords, and two-factor authentication codes. It also generated a new application-specific passcode on the compromised account, giving attackers ongoing access through legacy protocols such as IMAP or ActiveSync that bypass standard multi-factor authentication prompts entirely.

Microsoft has urged organizations still running on-premises Exchange Server 2016, 2019, or Subscription Edition to apply the Exchange Emergency Mitigation Service or the Exchange On-premises Mitigation Tool immediately, pending a permanent patch, since the flaw remains actively exploited.

Administrators should also review Outlook add-in permissions, audit mailbox folder ownership for unexpected Owner-level grants to the Default account, and treat any mailbox that opened a suspicious message as potentially compromised, regardless of subsequent password changes.

Organizations running Zimbra Collaboration Suite should confirm they have been updated beyond version 10.1.13 and review historical logs for the fragmented CSS import pattern associated with the earlier exploit. Given the group's demonstrated ability to maintain server-side persistence that outlives standard remediation steps, security teams are advised to inspect mailbox permission structures directly on the Exchange server rather than relying solely on endpoint reimaging or credential rotation to remove an intruder.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate