www.bleepingcomputer.com/news/secu…
The Russia-aligned group Laundry Bear (also tracked as Void Blizzard / TA488) is actively exploiting an Outlook Web Access vulnerability in email campaigns to deploy the sophisticated browser-based backdoor OWAReaper. Opening the malicious email is sufficient to trigger the exploit (“half-click”).
OWAReaper runs entirely inside the OWA browser context with no traditional host footprint, maintains persistence across browser restarts and credential changes, and provides long-term mailbox access plus dual command-and-control and exfiltration channels. Infrastructure for the campaign dates to March 2026, suggesting possible zero-day use before Microsoft’s out-of-band patch.