Laundry Bear (also known as Void Blizzard), a Russian state-sponsored hacking group, is exploiting an Outlook Web Access zero-day vulnerability in Microsoft Exchange to deliver the OWAReaper backdoor. The campaign targets organizations in Europe and the US for long-term mailbox persistence.
8 reports · 6 independenttech · other
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
The Russia-aligned hacking group TA488, also known as Laundry Bear or Void Blizzard, exploited a now-patched Microsoft Exchange Outlook Web Access flaw tracked as CVE-2026-42897 to access mailboxes through crafted webmail messages [bleepingcomputer.com#1][cybersecuritynews.com#1]. Proofpoint identified the campaign and named the browser-based implant OWAReaper, which attackers used against governm
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]