CVE-2026-42897 Outlook attack tied to Russian espionage group
Proofpoint says TA488 used an Outlook Web Access flaw against governments and companies, extending a no-click email tactic beyond Zimbra.
By Dominic Okoye · Staff Writer
· 3 min read
Proofpoint says a Russian espionage group it tracks as TA488, also known as Laundry Bear, used a CVE-2026-42897 Outlook attack against Microsoft Outlook Web Access on on-premises Exchange Server. The finding matters for security teams because the attack does not require a victim to click a link or open an attachment, only to view a malicious email in OWA.
The campaign extends a technique previously associated with Zimbra Collaboration Suite. According to Proofpoint, TA488 began exploiting the Outlook Web Access flaw one day before researchers and government agencies publicly detailed the group’s use of a Zimbra zero-day. Proofpoint said the OWA activity was aimed at government organizations in the United States and Europe, as well as companies in telecommunications, financial services, hospitality and aerospace.
Microsoft disclosed CVE-2026-42897 in May after reports that attackers were already using the bug. The vulnerability is a cross-site scripting flaw in the OWA component of on-premises Exchange Server. Proofpoint’s report connects that exploitation to a wider espionage operation, rather than treating it as isolated abuse of a single bug. Exchange Online is not affected, according to the reporting.
How does the Outlook Web Access attack work?
In this attack, the malicious email causes the browser to run attacker-controlled JavaScript inside the user’s authenticated OWA session when the message is opened. That makes the tactic different from standard phishing, where attackers typically need the target to click a link, download a file or enter credentials on a fake page.
Proofpoint said TA488 used an implant it calls OWAReaper rather than conventional endpoint malware. The implant operates within Outlook Web Access, leaving little evidence on the host machine, according to the researchers. Proofpoint said OWAReaper can communicate through two command-and-control channels, exfiltrate data through multiple methods and persist through browser restarts, password changes and even a full device rebuild because the access is tied to the mailbox rather than the Windows device.
The breadth of the targeting is notable. Espionage groups often run narrow collection campaigns against specific agencies, contractors or policy targets. Proofpoint said this operation appeared unusually broad and may have been designed to blend into normal email traffic. The company said TA488 continued to show interest in government and defense intelligence collection, while using generic lure themes that recipients might open, skim and then disregard.
Proofpoint also raised the possibility that TA488 had used CVE-2026-42897 before it was publicly known. The company cited attacker infrastructure dating back to March, roughly two months before Microsoft issued an out-of-band patch. If that timeline is correct, defenders were dealing with active exploitation before they had a disclosed vulnerability to track or remediate.
Microsoft did not immediately respond to questions from The Register, according to its report. Proofpoint’s assessment, if confirmed, would show TA488 adapting a low-interaction email compromise technique from Zimbra to a harder target in Outlook Web Access, increasing the risk for organizations that still run on-premises Exchange and rely heavily on email security controls tuned for links, attachments and endpoint payloads.
This story draws on original reporting from The Register.