Feeds.4Sysops
Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Russian-aligned TA488 group is exploiting a flaw in Microsoft Outlook Web Access (OWA) that allows them to maintain access to mailboxes even after password resets and device reimaging. This vulnerability enables the attackers to use an implant called OWAReaper, which grants them persistent server-side permissions by simply opening an email. The attack affects Microsoft Exchange servers and poses a significant risk to organizations that rely on OWA for email access. The exploitation method allows the attackers to bypass traditional security measures, making it challenging for organizations to secure their email environments. As of now, there are no specific patches or mitigations disclosed to address this vulnerability. Organizations are urged to monitor their OWA environments closely for unusual activity. The situation is critical as it involves state-sponsored actors and impacts enterprise-level security.
Key Points: • TA488 group exploits OWA flaw for persistent mailbox access. • OWAReaper implant allows access even after credential changes. • No current patches or mitigations available for affected systems.