Russian hackers Laundry Bear exploit Exchange OWA zero-day to deploy OWAReaper backdoor
This digest was compiled by AI from multiple sources — links to the originals are below.

Russian state-sponsored hacking group Laundry Bear exploits a zero-day vulnerability in Microsoft Exchange Outlook Web Access to deploy the OWAReaper backdoor, Proofpoint reported Thursday. The campaign targets government entities in the U.S. and Europe, along with telecom, financial, hospitality, and aerospace companies.
CVE-2026-42897 Exploit
The vulnerability, tracked as CVE-2026-42897, stems from improper HTML sanitization in Exchange OWA, allowing attackers to run arbitrary JavaScript when a user opens a crafted email. Laundry Bear set up attack infrastructure for the campaign in March 2026, nearly two months before Microsoft’s May 14 advisory. The flaw was exploited as a zero-day, with Proofpoint observing active attacks a week before its report.
OWAReaper Backdoor
The exploit delivers a backdoor named OWAReaper, which Proofpoint calls the most sophisticated malware delivered via half-click exploits. It runs entirely within the OWA reading pane, using a JavaScript loader and Base64-encoded payloads hidden in social media icon URLs after the ‘#’ character. OWAReaper incorporates subtle persistence mechanisms and represents an evolution of the ZimReaper malware used in earlier Zimbra attacks.
Campaign Lures and Sector Targets
The attackers used emails with benign subject lines such as supply-chain analysis, research updates, and tourism and gas market performance indicators. Targets included government entities in the U.S. and Europe, as well as firms in telecommunications, finance, hospitality, and aerospace. The messages contained no suspicious attachments or URLs, making them appear to be routine spam to recipients.
What's Next
Microsoft has patched the vulnerability, but it is unknown how many Exchange OWA instances have been updated. Researchers warn that the half-click technique could be replicated by other groups, posing a persistent threat to webmail platforms.
2 sources
Russian hackers Laundry Bear exploit Exchange OWA zero-day to deploy OWAReaper backdoor



