Kremlin-linked hackers exploit critical Exchange Server flaw to install persistent backdoor
Security researchers say a Russian state-sponsored group is using a maximum-severity Exchange Server vulnerability to compromise Outlook Web Access accounts and deploy a novel JavaScript implant.
Proofpoint researchers reported that the Russian state-backed TA488 group is actively exploiting a high-severity vulnerability in Microsoft Exchange Server to infiltrate unpatched Outlook Web Access accounts. The flaw, catalogued as CVE-2026-42897, is a cross-site-scripting issue that Microsoft rated as critical, provided mitigation advice in May and released a patch in July. TA488’s attack chain requires only the opening of a crafted email, after which a previously unseen JavaScript payload installs a bespoke browser extension named OWAReaper, designed for persistent access.
This “half-click” approach marks a notable upgrade in the group’s tradecraft, according to Proofpoint. The same group was earlier linked to zero-day exploits against Zimbra’s email platform, a finding jointly warned about by the National Security Agency. The emergence of OWAReaper is described as the most sophisticated backdoor delivered via such an exploit to date.
Why it matters
The exploit compromises corporate and government email accounts, exposing sensitive data and enabling long-term espionage.
In this story