threat-intel
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
High
Summary
Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and telecommunications companies. They are leveraging a sophisticated new implant, OWAReaper, delivered via half-click exploits, to steal credentials and maintain access even after re-imaging devices. The campaign began in March 2026, potentially utilizing a zero-day exploit, and employs multiple C2 channels and data exfiltration methods to evade detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
