Particle.news

Critical Outlook Web Access Flaw Used to Deploy In‑Browser Backdoor OWAReaper

Security researchers say the JavaScript implant can persist on Exchange servers after users change passwords, requiring server-side fixes rather than endpoint-only cleanup.

Overview

  • Proofpoint disclosed that attackers have run a concentrated campaign that began around July 22 using a cross-site scripting bug in Outlook Web Access identified as CVE-2026-42897.
  • The flaw lets embedded JavaScript run when a message is displayed in the Outlook web client, so simply viewing a crafted email can load the malicious code in what researchers call a 'half-click' exploit.
  • The payload, named OWAReaper, runs inside the browser context, removes traces from the original message, and uses stolen OAuth/EWS tokens and modified Exchange folder rights to maintain access without leaving typical host artifacts.
  • Researchers attribute the operation to the suspected Russia-linked group TA488 and report targeted intrusions against government agencies and firms in telecommunications, finance, aerospace, and hospitality in Europe and the U.S.
  • Microsoft has released patches for CVE-2026-42897 and experts advise admins to revoke OAuth/EWS tokens, audit and correct Exchange permissions, delete OWA local storage keys such as IndexedDB/PageDataPayload, and block known command-and-control addresses because passwords or device reinstalls may not remove the implant.