OWAReaper Backdoor Targets Microsoft Exchange Users


outlook clicking bug
Image credit: Microsoft

Russian state-sponsored hackers are exploiting a Microsoft Exchange Outlook Web Access vulnerability to deploy OWAReaper, a webmail backdoor designed for long-term mailbox access.

The group, known as Laundry Bear and Void Blizzard, is tracked by Proofpoint as TA488. Its targets include government organizations in the United States and Europe, along with telecommunications, financial, hospitality, and aerospace companies.

Attack Exploits CVE-2026-42897

The campaign exploits CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access.

The flaw allows malicious JavaScript to execute when a user opens a specially crafted email in the OWA reading pane. The attack requires no malicious attachment, link, or additional click.

Microsoft disclosed the vulnerability on May 14. However, available evidence indicates that Laundry Bear had already exploited it as a zero-day before the disclosure.

The attackers deliberately make the emails look unimportant. A recipient may open the message, dismiss it as junk, and avoid reporting it because it contains no obvious malicious links or attachments.

The messages hide JavaScript loaders and Base64-encoded payloads inside social media icon URLs. The malicious data appears after the # character, making the email harder to identify as an attack.

OWAReaper Removes Evidence and Collects Credentials

OWAReaper operates entirely inside the Outlook Web Access reading pane. Once it executes, the backdoor rewrites the original email on the Exchange server and removes evidence of the exploit.

It then collects information about the victim, including email address, username, and Outlook configuration details.

The malware also creates invisible browser elements that attempt to capture credentials automatically entered by a password manager or browser autofill feature.

OWAReaper searches for Outlook add-ins with ReadWriteMailbox permissions. When it finds a suitable add-in, it abuses that access to steal OAuth tokens.

Mailbox Permissions Create Server-Side Persistence

The backdoor can grant Owner-level mailbox permissions to the Exchange Default user across every mail folder. This configuration may allow an attacker to access the compromised mailbox through another authenticated account inside the organization.

Because Exchange stores these permissions on the server, reinstalling the victim’s computer may not remove the attacker. Changing the user’s password may also fail to block access if the malicious mailbox permissions and stolen OAuth tokens remain active.

OWAReaper creates another persistence mechanism through the Outlook Web Access offline cache. It enables OWA caching and injects a malicious iframe into messages stored in the browser’s IndexedDB database.

The iframe executes whenever the victim opens a poisoned message from the offline cache. This method operates separately from the server-side mailbox permissions.

Commands Hidden in GitHub and Email Messages

OWAReaper supports two command-and-control methods.

The first method uses encrypted commands hidden inside GitHub commit messages. The second relies on specially formatted emails sent directly to the compromised mailbox.

For data theft, the malware primarily sends encrypted information over HTTPS through image content delivery network domains. It encrypts data placed inside request paths with AES-CTR.

A secondary channel sends stolen information directly to an attacker-controlled server when the primary method fails.

Organizations Should Review Exchange Permissions

Proofpoint published a limited number of indicators of compromise, including malicious domains and HTML containing the exploit and payload.

Organizations should install Microsoft’s security update for CVE-2026-42897 and inspect their Exchange environments for signs of compromise. Administrators should review:

  • Mailbox permissions assigned to Default users
  • Outlook add-ins with extensive mailbox access
  • Suspicious OAuth token activity
  • Unusual GitHub API requests
  • Potentially poisoned messages stored in OWA caches

Password resets and device reinstallation may not fully remove OWAReaper because the attackers can maintain access through server-side permissions and offline cached messages.

In other security news, hackers have been found using hotel Wi-Fi to steal Microsoft 365 accounts, while Chaos ransomware is using msaRAT to hide traffic in Chrome and Edge.

To respond to emerging cyber threats, Microsoft has also released the new MAI-Cyber-1-Flash model.

Via BleepingComputer

More about the topics: exchange, malware, Outlook

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages