TA488, a Russian state linked group, has ported a phishing technique from Zimbra to on premises Exchange's Outlook Web Access, where opening the booby trapped message is enough to trigger the attack.
A Russian state-linked phishing crew tracked as TA488 has ported a "half-click" email exploit it used against Zimbra earlier in 2026 to on-premises Microsoft Outlook Web Access, Proofpoint researchers said Wednesday.
In a "half-click" attack, opening the booby-trapped message in the OWA reading pane is enough to fire attacker-controlled JavaScript in the authenticated browser session. There is no link to click and no attachment to open, so the standard "don't click anything" advice does not apply.
Proofpoint attributes the activity to TA488, also tracked as Void Blizzard and Laundry Bear, and says the crew began exploiting CVE-2026-42897, a cross-site scripting flaw in on-premises Exchange Server's OWA, on 22 July, one day after a joint Proofpoint-NSA disclosure on the group's parallel Zimbra abuse. The earliest attacker infrastructure tied to the OWA campaign was created in March 2026, roughly two months before Microsoft shipped an out-of-band patch in May.
The payload, dubbed OWAReaper, runs entirely inside the OWA reading pane, leaves virtually no host artifacts, and persists in compromised mailbox settings rather than on the device. It survives password changes and full re-imaging. Proofpoint says targeting was broad, hitting US and European government entities plus telecommunications, financial services, hospitality, and aerospace, with intentionally generic lure themes.
The scope is narrower than the wire framing suggests. Only on-premises Exchange Server deployments running OWA are exposed. Microsoft has not publicly confirmed Proofpoint's zero-day assessment, and no victim organizations have been named on the record.