Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
TA488 launched a July 2026 campaign exploiting CVE-2026-42897 in Outlook Web Access to deliver the browser-based implant OWAReaper against government, telecommunications, finance, hospitality, and aerospace targets. OWAReaper provides stealthy persistence, credential theft, command execution, and exfiltration through HTTPS or DNS, using infrastructure such as acocdn[.]com, asecdns[.]com, dnsrecursive[.]eu, and tdndns[.]com. #TA488 #OWAReaper #CVE-2026-42897 #OutlookWebAccess

Keypoints

  • TA488 began a new exploitation wave on 22 July 2026 using CVE-2026-42897, an XSS flaw in Outlook Web Access.
  • The campaign targeted US and European government entities plus telecommunications, financial, hospitality, and aerospace organizations.
  • The infection chain uses “half-click” email exploitation, where simply opening the message can trigger compromise.
  • The delivered payload is OWAReaper, a previously unknown JavaScript implant designed for persistence inside OWA.
  • OWAReaper can steal credentials, OAuth tokens, and mailbox access while surviving browser restarts, credential changes, and even device reimaging.
  • The implant supports command retrieval from GitHub commit messages or attacker emails and can exfiltrate data over HTTPS or DNS tunneling.
  • Proofpoint noted infrastructure dating back to March 2026, suggesting the vulnerability may have been used as a zero-day before Microsoft’s patch.

MITRE Techniques

  • [T1059.007 ] JavaScript – The exploit and payload execute in the browser using JavaScript embedded in the message body. [‘…runs arbitrary JavaScript…’]
  • [T1204.002 ] Malicious File or Link Opening – Compromise is triggered when the user opens the email in Outlook Webmail. [‘…if the email is opened in Outlook Webmail…’]
  • [T1210 ] Exploitation of Remote Services – TA488 abuses Outlook Web Access via CVE-2026-42897 to execute code on the Exchange server. [‘…abusing a cross-site scripting (XSS) vulnerability… in Outlook Web Access (OWA)’]
  • [T1555.004 ] Credentials from Password Stores – OWAReaper waits for browser autofill to capture saved OWA credentials from invisible form fields. [‘…waits for the browser’s autofill to enter the username and password…’]
  • [T1552.001 ] Credentials In Files – The implant steals OAuth tokens and other stored authentication artifacts through Outlook add-ins and related data. [‘…uses those add-ins to call GetClientAccessToken to steal OAuth tokens.’]
  • [T1036 ] Masquerading – The malware hides as normal OWA activity and uses generic lure content and CDN-like domain names to blend in. [‘…likely so the targeted user opens and skims the message, but dismisses the message as junk…’]
  • [T1090.001 ] Internal Proxy – Encrypted exfiltration is proxied through legitimate image CDN services before reaching attacker infrastructure. [‘…proxied through legitimate image CDN services…’]
  • [T1071.004 ] Application Layer Protocol: DNS – If HTTPS fails, the implant exfiltrates data using DNS label tunneling. [‘…will use DNS label tunneling to exfiltrate data inside the subdomains…’]
  • [T1567.002 ] Exfiltration to Cloud Storage – The implant fetches and relays commands through public GitHub commit messages. [‘…commands are either fetched from public GitHub commit messages…’]
  • [T1547.001 ] Registry Run Keys / Startup Folder – OWAReaper establishes persistence by storing encrypted code in localStorage and OWA settings for automatic re-execution. [‘…writes an encrypted version of itself… into the browser’s localStorage…’]
  • [T1205 ] Traffic Signaling – The script polls GitHub and offline email caches periodically for command retrieval. [‘…queries GitHub’s Commit Search API every 24 hours…’]

Indicators of Compromise

  • [Domain ] OWAReaper C2 and exfiltration infrastructure – asecdns[.]com, acocdn[.]com, and other domains including dnsrecursive[.]eu and tdndns[.]com
  • [SHA256 ] HTML message body containing exploit and OWAReaper payload – 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4
  • [File names ] Files exfiltrated or referenced by OWAReaper – msanalytics.json, ews_extensions_debug.json, and poison_wizard_error_dom.html
  • [ET rule / detection names ] Proofpoint detections tied to the activity – ETPRO EXPLOIT Microsoft Exchange Outlook Web Access (OWA) Cross-Site Scripting (CVE-2026-42897), ETPRO MALWARE OWAReaper C2 Beacon
  • [URI pattern ] HTTPS exfiltration path format – /assets/v1_


Read more: https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit