TA488 Exploits CVE-2026-42897 Outlook Flaw to Deploy OWAReaper Backdoor

Threat actor TA488 has launched a new campaign exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Outlook Web Access (OWA), to deploy a sophisticated JavaScript backdoor named OWAReaper.

The activity was observed on July 22, 2026, shortly before Proofpoint and the NSA released reporting on the threat group.

TA488 used compromised email accounts to distribute malicious messages to organizations in government, telecommunications, finance, hospitality, and aerospace.

The campaign’s wide targeting and high message volume are unusual for the group, possibly intended to make the emails resemble ordinary spam campaigns.

The attackers sent vague, informational emails with no links, attachments, or direct call to action.

Subject lines referenced topics such as semiconductor supply chains, global gas markets, public health surveillance, tourism metrics, and nuclear energy updates.

TA488 Deploys OWAReaper Backdoor

This social-engineering approach is designed to encourage recipients to open and briefly read the message without viewing it as suspicious enough to report.

If a recipient opens the email in a vulnerable OWA instance, CVE-2026-42897 allows attacker-controlled JavaScript to run inside the victim’s authenticated browser session.

TA488 “Semiconductor Supply Chain” lure email from July 2026 (Source: proofpoint)
TA488 “Semiconductor Supply Chain” lure email from July 2026 (Source: proofpoint)

The flaw exists because OWA does not properly sanitize certain HTML content in email messages.

TA488 used an onload event handler to trigger a small JavaScript loader that collected encoded payload fragments hidden within social media icon elements in the email body.

The browser ignored data after special characters in the image content, but the loader recovered and assembled those fragments into the OWAReaper implant.

This technique is more difficult to identify than TA488’s earlier campaigns targeting Zimbra webmail servers.

The group previously used a related payload called ZimReaper, but OWAReaper introduces stronger persistence, credential theft, mailbox permission abuse, and flexible command-and-control features.

OWAReaper runs entirely within the OWA reading pane. After execution, it overwrites the malicious message on the Exchange server to remove evidence of the exploit.

It also temporarily turns off right-click actions and pop-up windows while performing its operations.

HTTPS exfiltration method (Source: proofpoint)
HTTPS exfiltration method (Source: proofpoint)

The implant gathers the victim’s email address, username, and Outlook settings. It creates hidden fields positioned outside the visible browser area and waits for browser autofill to populate saved credentials.

This enables the malware to capture OWA usernames and passwords without displaying a visible prompt.

For browser-based persistence, OWAReaper stores an encrypted copy of itself in the PageDataPayload.OwaUserDefaultSettings localStorage key.

This is a legitimate OWA settings area used during the application’s sync and restore workflow. Each time the victim opens an OWA tab, the normal sync process can execute the stored malicious code again, Proofpoint said.

The malware also searches for Outlook add-ins with ReadWriteMailbox permissions. Where available, it attempts to obtain OAuth tokens via Exchange functions and to modify folder permissions.

It grants Owner-level access to the built-in “Default” user across mailbox folders, potentially allowing other authenticated accounts in the same organization to access the victim’s mailbox.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories