Domain
TA488, a Russia-aligned threat actor, initiated a campaign on July 22, 2026, exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The campaign targeted US and European government entities, along with telecommunications, financial, hospitality, and aerospace sectors. The attack employs half-click exploits requiring only email opening to trigger compromise, delivering OWAReaper, a novel JavaScript browser-based implant designed for persistent OWA access. OWAReaper operates stealthily within the browser context, featuring dual C&C channels via GitHub commit messages and inbound emails, plus HTTP and DNS exfiltration protocols. The implant survives browser reboots, credential rotation, and device re-imaging through multiple persistence mechanisms including localStorage manipulation, OAuth token theft, and Exchange folder permission modifications. Infrastructure dating to March 2026 suggests potential zero-day exploitation prior to Microsoft's May patch.
No sightings recorded yet