Russian Hackers Exploit Exchange OWA Zero-Day to Steal Emails Through Sophisticated OWAReaper Backdoor

Cybersecurity researchers have uncovered a new espionage campaign in which a Russian state-sponsored hacking group is exploiting a previously unknown Microsoft Exchange Outlook Web Access (OWA) vulnerability to gain long-term access to victims’ email accounts.

The campaign has been attributed to Laundry Bear, also known as Void Blizzard, a threat actor believed to be linked to Russian intelligence operations. According to email security firm Proofpoint, the attacks were detected approximately one week ago and have already targeted organizations across North America and Europe.

Wide Range of High-Value Targets

Researchers say the attackers are focusing on organizations that hold sensitive government and commercial information. Confirmed targets include government agencies in the United States and Europe, as well as companies operating in the telecommunications, financial services, hospitality, and aerospace sectors.

The campaign appears to be aimed at long-term cyber espionage rather than financial gain, with attackers seeking persistent access to confidential email communications.

Zero-Day Vulnerability Exploited

At the center of the campaign is CVE-2026-42897, a previously unknown (zero-day) cross-site scripting (XSS) vulnerability affecting Microsoft Exchange Outlook Web Access (OWA).

The flaw allows attackers to execute arbitrary JavaScript code within a user’s browser when the victim opens a specially crafted email through the OWA web interface. Because the malicious code runs in the security context of the authenticated user, attackers can manipulate web sessions, access mailbox content, and perform unauthorized actions without requiring the victim’s password.

Security researchers warn that simply opening the malicious email in Outlook Web Access is sufficient to trigger the exploit.

OWAReaper Backdoor Enables Persistent Access

Following successful exploitation, the attackers deploy a sophisticated backdoor dubbed OWAReaper.

Unlike traditional malware that infects a victim’s computer, OWAReaper operates by maintaining long-term access to the compromised webmail session. The malware enables threat actors to monitor email communications, steal sensitive messages, collect authentication tokens, and continue accessing mailboxes even after the initial compromise.

Researchers describe the tool as highly stealthy because much of its activity occurs within legitimate webmail sessions, making detection significantly more difficult for traditional security solutions.

Sophisticated Espionage Operation

Proofpoint believes the campaign reflects the advanced capabilities of state-sponsored cyber operators. By abusing a browser-based vulnerability instead of relying on conventional malware downloads, the attackers can bypass many endpoint security defenses while maintaining persistent access to valuable intelligence.

The campaign highlights an increasing trend among advanced persistent threat (APT) groups to target cloud services and web-based enterprise applications rather than traditional desktop software.

Organizations Urged to Strengthen Defenses

Cybersecurity experts recommend that organizations using Microsoft Exchange Outlook Web Access take immediate steps to reduce their exposure. Administrators should apply any available security updates as soon as they are released, closely monitor OWA activity for suspicious behavior, enable multi-factor authentication (MFA), review mailbox access logs, and deploy advanced email security solutions capable of detecting malicious messages before they reach users.

Security teams are also encouraged to educate employees about phishing attacks and unusual email behavior, as attackers continue to rely on carefully crafted emails to initiate compromises.

Growing Threat to Enterprise Email Security

The discovery of the OWAReaper campaign demonstrates how state-sponsored threat actors continue to exploit previously unknown software vulnerabilities to conduct cyber espionage. As organizations increasingly rely on web-based email platforms for business communications, vulnerabilities affecting these services have become attractive targets for nation-state attackers seeking long-term intelligence collection.

Researchers continue to investigate the campaign and expect additional technical details, indicators of compromise (IOCs), and mitigation guidance to be released as the investigation progresses.

Irfan Latif

Irfan Latif