OWAReaper is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
OWAReaper is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed July 30, 2026; most recent activity July 30, 2026.
The Russian-aligned TA488 group is exploiting a flaw in Microsoft Outlook Web Access (OWA) that allows them to maintain access to mailboxes even after password resets and device reimaging. This vulnerability enables the…
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent…
OWAReaper is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning OWAReaper on ThreatCluster is dated July 30, 2026.
Across ThreatCluster reporting, OWAReaper most frequently co-occurs with Laundry Bear, Ta488, Void Blizzard, Malware, CVE-2026-42897, among 12 tracked related entities.
The most significant recent cluster is “Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access” (2 articles · Updated July 30, 2026). OWAReaper appears across 2 threat clusters in total, listed above with sources.
OWAReaper appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.