Laundry Bear, also tracked as Void Blizzard and TA488, is using the CVE-2026-42897 Outlook Web Access XSS flaw in half-click email attacks to deliver the OWAReaper backdoor. The campaign targets government and industry organizations across the U.S. and Europe and uses advanced persistence, credential theft, and multi-channel command-and-control to maintain long-term mailbox access. #LaundryBear #VoidBlizzard #TA488 #CVE-2026-42897 #OWAReaper #MicrosoftExchange #OutlookWebAccess
Keypoints
- Laundry Bear is exploiting the CVE-2026-42897 OWA flaw in email campaigns.
- The attacks use a half-click XSS technique that triggers when a user opens a crafted email.
- The payload delivered is the OWAReaper backdoor, an evolution of ZimReaper.
- OWAReaper steals credentials and maintains mailbox access through server-side permissions.
- The malware uses multiple C2 and exfiltration methods, including GitHub, HTTPS, and DNS.