Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

acocdn.com

TLP:CLEAR
Active

Domain

Description

TA488, a Russia-aligned threat actor, initiated a campaign on July 22, 2026, exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The campaign targeted US and European government entities, along with telecommunications, financial, hospitality, and aerospace sectors. The attack employs half-click exploits requiring only email opening to trigger compromise, delivering OWAReaper, a novel JavaScript browser-based implant designed for persistent OWA access. OWAReaper operates stealthily within the browser context, featuring dual C&C channels via GitHub commit messages and inbound emails, plus HTTP and DNS exfiltration protocols. The implant survives browser reboots, credential rotation, and device re-imaging through multiple persistence mechanisms including localStorage manipulation, OAuth token theft, and Exchange folder permission modifications. Infrastructure dating to March 2026 suggests potential zero-day exploitation prior to Microsoft's May patch.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
Pattern Type
STIX
Confidence
75%
Valid From
Aug 1, 2026 18:02
Total Sightings
0
Added
Aug 1, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of acocdn.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.