Russian state hackers are targeting unpatched Microsoft Outlook’s Exchange Server with a maximum-severity vulnerability to steal sensitive information. TA488, working on behalf of the Kremlin, has been exploiting this flaw to backdoor systems and install malware through simple email opens.
The group, also known as Laundry Bear and Void Blizzard, was previously spotted in attacks using a zero-day exploit from Zimbra’s email service. Now they are taking advantage of CVE-2026-42897, an XSS vulnerability that Microsoft patched but not before it was exploited as a half-click attack vector.
Malicious JavaScript is used to install a custom-built browser extension, OWAReaper, granting attackers persistent access to victims’ Outlook Web Access accounts. This sophisticated backdoor demonstrates the group’s improved tradecraft and capability in exploiting vulnerabilities.
Proofpoint, working with the NSA, has warned of this threat, urging users to patch their systems immediately to avoid compromise. The revelation underscores the ongoing cyber arms race between state actors and cybersecurity firms.







