Skip to content

TA488 Exploits Outlook Half

Gbhackers Mayura Kathir July 30, 2026

TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full host re‑imaging. The operation exploits CVE‑2026‑42897, a cross‑site scripting flaw in OWA disclosed by Microsoft in May 2026 and confirmed to be actively […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Malware (1)

Platforms (1)