TA488 half-click Outlook Web Access espionage campaign
Campaign
Summary
Hide ▲
Show ▼
TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Server. The activity began on July 22, 2026 and targeted U.S. and European government entities plus the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint said the campaign deployed OWAReaper, a browser-based implant that runs in the OWA reading pane, rewrites emails on the server, and persists through OAuth token theft and Default-user folder grants. Microsoft released Exchange security updates, and Proofpoint recommended revoking Exchange Web Services tokens, removing unauthorized folder grants, and clearing OWA offline storage.
Related Happenings
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
H score34
First: 24.07.2026 20:50
Last: 24.07.2026 20:50
Sources 1
About this happening:
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
CampaignAbout this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Pink new extortion brand within The Com
Threat Actor MetaAbout this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Timeline
-
29.07.2026 18:10 2 articles · 9d ago
TA488 begins half-click OWA campaign against on-premises Exchange Server
Exploitation ObservedTA488, also tracked as Void Blizzard and Laundry Bear, began a campaign on July 22, 2026 that used a half-click exploit against on-premises Outlook Web Access (OWA) on Exchange Server. The messages exploited CVE-2026-42897 to execute JavaScript inside the victim's authenticated session and deploy the browser-resident implant OWAReaper against US and European government entities and organizations in telecommunications, financial, hospitality, and aerospace.
Show sources
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10
-
29.07.2026 18:10 3 articles · 9d ago
Proofpoint details OWAReaper persistence and Microsoft releases Exchange security updates
Technical Analysis UpdateOn July 29, 2026, Proofpoint detailed OWAReaper as a JavaScript implant that ran in the OWA reading pane with no conventional file on disk, rewrote the original email on the server, hid encrypted code in browser localStorage, and used a hidden iframe in OWA's offline IndexedDB cache to re-infect a re-imaged host. The report also described server-side mailbox persistence through OAuth token theft and Default-user folder grants, and noted that Microsoft had released Exchange security updates while recommending Exchange Web Services token revocation, removal of unauthorized folder grants, and clearing OWA offline storage.
Show sources
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack — www.infosecurity-magazine.com — 29.07.2026 18:10
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access — www.bleepingcomputer.com — 30.07.2026 02:44
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — thehackernews.com — 30.07.2026 10:40