VMTech
Discuss a project

Laundry Bear uses CVE-2026-42897 to preserve access to Microsoft OWA mailboxes

Laundry Bear uses CVE-2026-42897 to preserve access to Microsoft OWA mailboxes

Proofpoint reported on July 30, 2026, that Laundry Bear has been exploiting the patched CVE-2026-42897 in Microsoft Outlook Web Access since July 22. The cross-site scripting flaw carries a CVSS score of 8.1 and has affected U.S. and European government entities alongside telecommunications, financial, hospitality, and aerospace organizations.

An email only needs to be opened

The campaign uses compromised accounts to distribute vague messages about supply chains, research, tourism, or gas markets. They contain neither links nor attachments and require no deliberate interaction: viewing one in a vulnerable OWA reading pane triggers the exploit.

Embedded JavaScript uses an onload event to reconstruct and execute a Base64 payload concealed in social media icons. The broad mailing volume helps the operation resemble ordinary spam, while the neutral subject matter makes recipients more likely to open and skim the message.

OWAReaper establishes layered persistence

The exploit installs OWAReaper, a browser-based JavaScript implant derived from ZimReaper. It rewrites the malicious email on the Exchange server to remove exploit content, gathers account and Outlook settings, and creates invisible fields designed to capture credentials saved by browser autofill.

OWAReaper stores an encrypted copy of itself in localStorage, allowing execution whenever OWA is opened. It also places a hidden iframe in the offline IndexedDB message cache. If a suitable Outlook add-in has ReadWriteMailbox permission, the implant can steal OAuth tokens and grant the Default user Owner-level access to every mail folder.

This persistent access lives on the server-side and requires deliberate removal from the Exchange server; credential rotation and even full re-imaging of the targeted user's device will not evict the actor.

Commands arrive through GitHub commit searches every 24 hours or specially formatted inbound emails. Exfiltration uses AES-CTR-encrypted HTTPS paths, with DNS tunneling as a fallback. For businesses, patching OWA is only the first step: teams should audit Exchange folder permissions, privileged add-ins, OAuth tokens, active sessions, browser storage, and cached messages before treating an affected mailbox as clean.

#cybersecurity#emailsecurity#microsoftowa#threatintel
Open analytics
On the site 1 views
min read 2 30.07.2026
Instagram

Laundry Bear uses CVE-2026-42897 to preserve access to Microsoft OWA mailboxes

Open the post on Instagram ↗