Kremlin-Linked Hackers Exploit Critical Exchange Server Flaw with Stealthy New Malware
Russian state-sponsored hackers are actively exploiting a maximum-severity vulnerability in Microsoft Exchange Server to backdoor unpatched systems and steal sensitive credentials. Security researchers at Proofpoint identify the threat actor as TA488, a group operating on behalf of the Kremlin and also tracked as Laundry Bear and Void Blizzard. The group previously targeted Zimbra email services using similar techniques, and their expansion to Exchange Server raises new concerns about their growing capabilities.
The flaw, tracked as CVE-2026-42897, is a cross-site scripting vulnerability that Microsoft patched in July after providing mitigation guidance in May. What makes this attack particularly dangerous is that it requires no interaction beyond a user simply opening a malicious email in their Outlook Web Access account. The exploit installs a custom JavaScript browser extension called OWAReaper, which Proofpoint describes as the most sophisticated backdoor ever delivered through a half-click attack method.
OWAReaper grants attackers persistent access to compromised accounts that survives credential rotations and even disk re-imaging, making it extremely difficult to eradicate. The malware allows continuous theft of confidential information and ongoing surveillance of victim communications. Organizations running unpatched Exchange Server installations face immediate risk and should apply Microsoft's July security updates without delay to close this critical vulnerability.