The emergent Russian advanced persistent threat (APT) actor dubbed Laundry Bear has initiated a new wave of exploitation activity abusing a Microsoft Outlook Web Access (OWA) cross-site scripting (XSS) flaw, mere hours after a National Cyber Security Centre (NCSC) alert directing attention to the group’s abuse of a similar flaw.
On 23 July, a multinational coalition of cyber authorities, including the NCSC and its American partners, detailed Laundry Bear’s novel ‘half-click’ phishing technique – requiring no user interaction beyond opening a tainted email – that leveraged another XSS flaw, CVE-2025-66376, in Zimbra Collaboration Suite (ZCS). The agencies said the exploit had likely been developed with the assistance of an artificial intelligence (AI) model.
But according to a Proofpoint research team – which tracks Laundry Bear as TA488 – approximately 24 hours prior to the NCSC’s disclosure, the group pivoted to the OWA flaw, CVE-2026-42897, a critical issue that arises from the improper neutralisation of input during web page generation.
CVE-2026-42897 was disclosed by Microsoft on 14 May, shortly after May’s Patch Tuesday update, and appeared on the Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue shortly thereafter.
The Proofpoint team, comprising researchers Greg Lesnewich, Stuart del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan and Mark Kelly, said: “On 22 July 2026 – the day prior to Proofpoint’s joint release with the NSA – TA488 initiated a new wave of exploitation abusing … CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyse, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity.
“TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny.
“If the email is opened in Outlook Webmail, the Outlook Exchange server mishandles the HTML from the message and runs arbitrary JavaScript. This executes the payload in the message body, an implant Proofpoint calls OWAReaper,” they said.
The team said OWAReaper was the “most sophisticated” backdoor delivered via such an exploit that Proofpoint had ever observed. An evolution of the ZImReaper payload, with which it shares multiple behavioural and coding overlaps, OWAReaper is notable for a subtle set of persistence mechanisms that enable it to obtain full access to the mailbox of any authenticated user in the same organisation as the initial victim and making it very hard to remove even with credential rotation and full re-imaging of the target’s device.
And even if the affected device is re-imaged, OWAReaper can return by means of a hidden iframe added to messages stored in OWA’s offline IndexedDB message cache. The iframe executes again should the victim open a poisoned email from the cache, thus reinfecting themselves.
Proofpoint said the overall modus operandi – such as the use of half-click XSS exploits, the use of encoded DNS exfiltration, and the focus on email and credential theft – left it pretty confident that Laundry Bear is the driving force behind the OWA campaign.
They said the group had “greatly improved” its opsec measures and was writing more subtle and capable malwares than before. Moreover, its broader targeting of OWA highlights a wider risk to end-user organisations than its ZCS campaign – although this said, Laundry Bear does seem to still be targeting intelligence collection in support of its paymasters’ geopolitical goals.
Proofpoint also noted that there was some evidence to suggest Laundry Bear has been abusing CVE-2026-42897 on a smaller scale as far back as March 2026, which suggests it is feasible the flaw was used as a zero-day.
“If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488,” they said.

