Find notable cyber news and cases, enriched with sources, timelines, and signals.

TA488 half-click Outlook Web Access espionage campaign

Campaign
First reported
Last updated
Happening score
H score 42
3 unique sources, 3 articles

Summary

Hide ▲

TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Server. The activity began on July 22, 2026 and targeted U.S. and European government entities plus the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint said the campaign deployed OWAReaper, a browser-based implant that runs in the OWA reading pane, rewrites emails on the server, and persists through OAuth token theft and Default-user folder grants. Microsoft released Exchange security updates, and Proofpoint recommended revoking Exchange Web Services tokens, removing unauthorized folder grants, and clearing OWA offline storage.

Related Happenings

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
H score34 First: 24.07.2026 20:50 Last: 24.07.2026 20:50 Sources 1

About this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Pink new extortion brand within The Com

Threat Actor Meta
H score31 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Timeline

  1. 29.07.2026 18:10 2 articles · 9d ago

    TA488 begins half-click OWA campaign against on-premises Exchange Server

    Exploitation Observed

    TA488, also tracked as Void Blizzard and Laundry Bear, began a campaign on July 22, 2026 that used a half-click exploit against on-premises Outlook Web Access (OWA) on Exchange Server. The messages exploited CVE-2026-42897 to execute JavaScript inside the victim's authenticated session and deploy the browser-resident implant OWAReaper against US and European government entities and organizations in telecommunications, financial, hospitality, and aerospace.

    Show sources
  2. 29.07.2026 18:10 3 articles · 9d ago

    Proofpoint details OWAReaper persistence and Microsoft releases Exchange security updates

    Technical Analysis Update

    On July 29, 2026, Proofpoint detailed OWAReaper as a JavaScript implant that ran in the OWA reading pane with no conventional file on disk, rewrote the original email on the server, hid encrypted code in browser localStorage, and used a hidden iframe in OWA's offline IndexedDB cache to re-infect a re-imaged host. The report also described server-side mailbox persistence through OAuth token theft and Default-user folder grants, and noted that Microsoft had released Exchange security updates while recommending Exchange Web Services token revocation, removal of unauthorized folder grants, and clearing OWA offline storage.

    Show sources