Russian Espionage Group Expands Email Attack to Microsoft Outlook, Targeting Multiple Sectors
A Russian espionage group known as TA488, or 'Laundry Bear,' has expanded its cyber attack tactics from Zimbra to Microsoft Outlook Web Access (OWA). According to cybersecurity firm Proofpoint, the group is exploiting a cross-site scripting flaw, CVE-2026-42897, in the OWA component of on-premises Exchange Server. This attack method allows the execution of attacker-controlled JavaScript within a victim's authenticated mail session without requiring the victim to click on a link or download a file. The campaign targets government organizations in the U.S. and Europe, as well as sectors like telecommunications, financial services, hospitality, and aerospace. The attack is characterized by its broad scope, potentially to blend in with regular email traffic, and uses a browser implant called OWAReaper, which is difficult to detect and can survive various security measures.