Overview
- Proofpoint disclosed that attackers have run a concentrated campaign that began around July 22 using a cross-site scripting bug in Outlook Web Access identified as CVE-2026-42897.
- The flaw lets embedded JavaScript run when a message is displayed in the Outlook web client, so simply viewing a crafted email can load the malicious code in what researchers call a 'half-click' exploit.
- The payload, named OWAReaper, runs inside the browser context, removes traces from the original message, and uses stolen OAuth/EWS tokens and modified Exchange folder rights to maintain access without leaving typical host artifacts.
- Researchers attribute the operation to the suspected Russia-linked group TA488 and report targeted intrusions against government agencies and firms in telecommunications, finance, aerospace, and hospitality in Europe and the U.S.
- Microsoft has released patches for CVE-2026-42897 and experts advise admins to revoke OAuth/EWS tokens, audit and correct Exchange permissions, delete OWA local storage keys such as IndexedDB/PageDataPayload, and block known command-and-control addresses because passwords or device reinstalls may not remove the implant.