OWAReaper is a browser-resident JavaScript backdoor used in espionage operations attributed to the Russia-aligned threat actor TA488, also tracked as Laundry Bear and Void Blizzard. It is designed specifically for persistent compromise of on-premises Microsoft Exchange Outlook Web Access (OWA) by exploiting CVE-2026-42897, a cross-site scripting flaw that allows attacker-controlled JavaScript to execute when a victim opens a crafted email in OWA. The intrusion method has been characterized as a half-click attack because message viewing alone can trigger execution without requiring a link click or attachment open.
The implant executes entirely inside the OWA reading pane and is notable for leaving little or no conventional host-level malware footprint. After execution, it can rewrite the original message on the Exchange server to remove exploit content, reducing forensic visibility. OWAReaper collects mailbox and user context information, including account and Outlook configuration details, and attempts credential theft by creating invisible form elements to trigger browser autofill. It also searches for Outlook add-ins with mailbox write permissions and abuses token-access functionality to obtain OAuth tokens.
OWAReaper implements multiple persistence mechanisms across both browser and server-side layers. It can store an encrypted copy of itself in browser storage used by OWA so that opening new OWA tabs causes re-execution. It also enables offline caching and poisons OWA's IndexedDB message cache by inserting hidden content into cached messages, allowing reinfection when cached mail is reopened. More significantly, it abuses Exchange folder-permission operations to grant broad mailbox access through the default organizational user context, creating server-side persistence that can survive password changes and even device reimaging until explicitly remediated on the mail server.
For command and control, OWAReaper supports covert channels that include retrieving encrypted instructions from GitHub commit messages and parsing specially formatted inbound emails available within the mailbox cache. It supports toolkit replacement, command-and-control rotation, and arbitrary JavaScript execution. Exfiltration is performed primarily over HTTPS using encrypted request paths, with fallback mechanisms including direct server communication and DNS-based exfiltration. Reported targeting has included government entities in the United States and Europe as well as organizations in telecommunications, finance, hospitality, and aerospace. OWAReaper is widely assessed as an evolution of the earlier ZimReaper implant used by the same actor against Zimbra environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The activity uses OWAReaper, a sophisticated backdoor delivered through malicious emails exploiting CVE-2026-42897. CVE-2026-42897 is a cross-site scripting vulnerability caused by inadequate HTML sanitization in OWA. A specially crafted email can contain malicious JavaScript that executes when the recipient opens the message in OWA. | The activity uses OWAReaper, a sophisticated backdoor delivered through malicious emails exploiting CVE-2026-42897.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity uses OWAReaper, a sophisticated backdoor delivered through malicious emails exploiting CVE-2026-42897.
The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client.
The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
The group used ordinary-looking subjects concerning supply chains, research updates, tourism, gas markets and other industry-related information, making the messages less likely to be treated as malicious.
The emails contained JavaScript loaders and Base64-encoded payload fragments hidden within URLs associated with social-media-style icons.
Proofpoint, who detected emails carrying the concealed exploit hitting inboxes. “The subject lines and lures are banal, likely so the targeted user opens and skims the message, but dismisses the message as junk without reporting it, especially given that there are no suspicious URLs or attachments present,”
It periodically searches GitHub commit messages for encrypted commands containing the victim's email address and can also receive commands through specially formatted emails stored in OWA's cache.
The emails contained JavaScript loaders and Base64-encoded payload fragments hidden within URLs associated with social-media-style icons. Once triggered, the code assembled and executed the OWAReaper payload.
It searches for Outlook add-ins with "ReadWriteMailbox" permissions and can use the "GetClientAccessToken" operation to obtain OAuth tokens.
For data theft, OWAReaper primarily uses HTTPS with encrypted URI paths that can be routed through image CDN services.
Exfiltration occurred over HTTPS, proxied through legitimate image content delivery networks
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser-based backdoor that operates within Outlook Web Access (OWA) to maintain persistent access to victims' mailboxes. It collects mailbox and configuration data, attempts credential capture via browser autofill abuse, obtains OAuth tokens through Outlook add-ins, modifies Exchange folder permissions for server-side persistence, re-executes via poisoned offline cache content, and supports C2 and exfiltration over HTTPS, direct server fallback, and DNS.
Malware deployed by TA488 following exploitation of CVE-2026-42897.
A previously unknown custom-built JavaScript browser-based implant/backdoor delivered via a half-click exploit against Outlook Web Access. It installs a malicious browser extension to provide persistent access to victims’ OWA accounts and facilitate credential and confidential information theft.
A browser-executed Exchange/OWA backdoor delivered via exploitation of CVE-2026-42897. It rewrites the original email to remove exploit code, suppresses user interaction, gathers victim email and Outlook settings, attempts credential capture, persists via browser storage so it relaunches with new OWA tabs, abuses Outlook add-ins to steal OAuth tokens and grant mailbox permissions, and can exfiltrate data over HTTPS or DNS while receiving commands from GitHub commit messages or inbound attacker emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.