Overview
- Security firm Proofpoint says the Russia-aligned group TA488, known as Laundry Bear, began a new Outlook Web Access exploit campaign that started on July 22 and delivered a browser-resident backdoor called OWAReaper.
- OWAReaper runs inside the OWA reading pane and hides an encrypted copy in browser localStorage while also planting hidden iframes in OWA’s offline IndexedDB so the implant can re-execute after a machine is cleaned or re-imaged.
- The implant abuses server-side mailbox settings by stealing OAuth tokens and granting the Exchange 'Default' user owner-level permissions on folders, which lets attackers access any mailbox from any authenticated account in the same organization.
- Proofpoint found the campaign targeted U.S. and European government and industry accounts across telecommunications, finance, hospitality and aerospace and observed infrastructure dating to March 2026 that makes pre-disclosure exploitation plausible.
- Researchers urge immediate action: apply Microsoft’s Exchange/OWA updates, revoke Exchange Web Services and OAuth tokens, remove Default-user folder grants, clear OWA offline caches and localStorage, and hunt the published indicators because credential rotation alone may not remove access.