Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access

Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access

First seen 30 Jul 2026, 13:40 UTC ThehackernewsFeeds.4Sysops 81% similarity 72.0

Article Content

Browse articles
ThreatCluster

The Russian-aligned TA488 group is exploiting a flaw in Microsoft Outlook Web Access (OWA) that allows them to maintain access to mailboxes even after password resets and device reimaging. This vulnerability enables the attackers to use an implant called OWAReaper, which grants them persistent server-side permissions by simply opening an email. The attack affects Microsoft Exchange servers and poses a significant risk to organizations that rely on OWA for email access. The exploitation method allows the attackers to bypass traditional security measures, making it challenging for organizations to secure their email environments. As of now, there are no specific patches or mitigations disclosed to address this vulnerability. Organizations are urged to monitor their OWA environments closely for unusual activity. The situation is critical as it involves state-sponsored actors and impacts enterprise-level security.

Key Points: • TA488 group exploits OWA flaw for persistent mailbox access. • OWAReaper implant allows access even after credential changes. • No current patches or mitigations available for affected systems.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
Russian hackers exploit OWA flaw
TA488 group uses OWAReaper to maintain mailbox access post-password resets, affecting Microsoft Exchange servers.
Feeds.4Sysops
2026-07-30
Details of the attack method revealed
The attack allows persistent access by opening a single email, creating server-side permissions.
Thehackernews

Community

Browse all →