Wed 29 Jul 2026 / 14:58 ET
Kernel
Security 3 min read

Laundry Bear OWA exploit expanded email-theft campaign, Proofpoint says

Proofpoint says Laundry Bear used an Outlook Web Access bug and a JavaScript implant to steal emails and credentials from governments and companies.

Dana Voss

By Dana Voss / Security Correspondent

Laundry Bear OWA exploit expanded email-theft campaign, Proofpoint says
img: The Record

The Laundry Bear OWA exploit was running sooner and more broadly than public warnings last week indicated, according to new research from Proofpoint. The company said Wednesday that the Russian state-linked espionage group began abusing a Microsoft Outlook Web Access vulnerability one day before governments and security firms warned about the same group’s attacks on Zimbra webmail users.

Proofpoint said the operators, tracked by the company as TA488 and also known as Void Blizzard, aimed the campaign at U.S. and European government entities and organizations in telecommunications, finance, hospitality and aerospace. As in the Zimbra activity disclosed on July 23, the objective was mailbox access: stolen email and account credentials.

The finding widens the known timeline for Laundry Bear’s recent webmail operations. Last week’s public alert said the group had exploited a Zimbra Collaboration Suite flaw as recently as February. Proofpoint now says the same threat actor started preparing a separate Outlook Web Access campaign in March and used a previously unknown browser implant to keep access inside victims’ webmail sessions.

What is the Laundry Bear OWA exploit?

Outlook Web Access, or OWA, is Microsoft Exchange’s browser-based email interface. Proofpoint said Laundry Bear used a bug in OWA to trigger an infection chain when a target opened a malicious email, a technique the company describes as a “half-click” exploit because the victim did not need to open an attachment or follow a link.

The OWA vulnerability is tracked as CVE-2026-42897. Proofpoint said it is feasible that Laundry Bear used the bug before it was publicly known, which would make the activity zero-day exploitation, but the company did not present that as confirmed. The flaw was first publicized and patched in May, and Microsoft posted remediation information in mid-July.

Proofpoint said it did not have enough time to analyze a July 22 discovery and include it in the earlier public alert. That explains why the OWA activity landed after the initial Zimbra warning, even though the underlying campaign had already begun.

What did OWAReaper do?

Proofpoint said the infection chain ended with a previously unseen JavaScript implant it named OWAReaper. The implant was built to persist inside Outlook Web Access, giving the attackers a way to maintain access to the target’s browser-based mailbox rather than just grab credentials once and leave.

The company described the malware campaign as a step up in Laundry Bear’s tooling. Proofpoint said OWAReaper was the most sophisticated backdoor it had seen delivered through half-click exploitation at the time of writing, citing its persistence methods. Greg Lesnewich, one of the report’s authors, also said on Bluesky that it was “one of the coolest implants we’ve ever examined.”

Dutch authorities and Microsoft identified Laundry Bear as an advanced persistent threat group last year. U.S. prosecutors have linked the group to Yutek-NN, a Russian IT firm with ties to the FSB intelligence agency, according to Reuters.

The practical point for Exchange administrators is narrower than the attribution fight: this was a webmail compromise campaign, and the relevant OWA flaw has a patch history and Microsoft remediation guidance. Proofpoint’s report says the attackers were interested in mailboxes, credentials and staying power, which is exactly the kind of access that makes email servers such useful intelligence collection targets.

This story draws on original reporting from The Record.

More Security/

view all ↗