Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian cyber espionage group TA488 has exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Outlook Web Access (OWA) to maintain persistent mailbox access even after credential changes. The implanted JavaScript malware, dubbed OWAReaper, operates stealthily within the OWA browser context, harvesting credentials, stealing OAuth tokens, and surviving device re-imaging by leveraging server-side persistence on Exchange servers and hidden offline cache elements. This advanced half-click exploit campaign targets various sectors including government and finance, enabling the actor to maintain long-term access that cannot be removed by credential rotation alone.

https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top