Laundry Bear’s webmail hackers had more in store after February, report says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42897 | Cross-Site Scripting in Microsoft Exchange Server Actively Exploited by Laundry Bear CVE-2026-42897 is an improper-neutralization flaw (CWE-79) in Microsoft Exchange Server that lets an unauthenticated remote attacker perform cross-site scripting and carry out spoofing. Per the CVSS vector (AV:N/PR:N/UI:R), exploitation requires a victim to interact with attacker-controlled content — reported attacks by the Russian actor Laundry Bear (TA488) trigger when a crafted email is opened in Exchange's webmail interface (Outlook Web Access). The attacker gains the ability to spoof the victim within their webmail session, and reported intrusions show mailbox access persisting even after organizations rotate credentials. Any organization running on-premises Microsoft Exchange Server or Exchange Server Subscription Edition is potentially exposed, particularly those publishing webmail to the internet; specific affected version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-15 and carries a very high EPSS score of 71.2%, though no public proof-of-concept is known. Do: Apply Microsoft's security update for CVE-2024-42897 to all on-premises Exchange and Exchange Subscription Edition servers per vendor guidance — no specific patch versions are provided in the available data, so consult the vendor advisory for build numbers. Federal agencies must patch or apply mitigations per BOD 22-01 given the KEV listing. Because reported attacks (Laundry Bear/TA488) maintain mailbox access after password resets, treat any suspected compromise as persistent: review OWA access logs and inbox rules for anomalies, and invalidate active webmail sessions and tokens, not just credentials. | 6.1 | 71% | KEV |
| large≈20,000+ internet-exposed Exchange servers (public-scan reporting) |
Full article432 words · extracted from therecord.media · click to collapse
Researchers say the Russian state-linked hacking group tracked as Laundry Bear has been more active in recent months than originally thought. Government agencies and cybersecurity companies warned on July 23 that the cyber-espionage group was abusing a vulnerability in Zimbra Collaboration Suite’s webmail platform. On Wednesday, researchers at Proofpoint issued an update saying that the same hackers began exploiting a bug in Microsoft Outlook Web Access (OWA) a day before the international alert. Laundry Bear targeted “US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors,” the researchers said. The goal, as with the campaign against Zimbra users, was to steal emails and account credentials. The malware campaign represented “an improvement in the group’s tradecraft and capability,” Proofpoint said. The company said it had not seen any activity by the group between February and July 22. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA,” the researchers said, adding that it’s “feasible” that Laundry Bear was exploiting the vulnerability as a zero-day. Laundry Bear compromised accounts with “half-click” exploits, meaning that simply opening an email was enough to begin the infection chain, Proofpoint said. OWAReaper itself “is the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing, primarily due to its suite of subtle persistence mechanisms,” the researchers said. Greg Lesnewich, one of the report’s authors, said on social media that it was “one of the coolest implants we’ve ever examined.” Laundry Bear, also tracked as TA488 and Void Blizzard, started laying the groundwork for the OWAReaper campaign in March, Proofpoint said. The OWA bug, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted additional remediation information in mid-July. Proofpoint said it did not have sufficient time to analyze and include the July 22 discovery into its alert last week. Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. U.S. prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.
No previous article
No new articles
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russia-hackers-outlook-webmail-malware