You Rotated the Credentials and Re-Imaged the Laptop. The Russians Still Have the Mailbox.
Updated: Aug 11
Proofpoint published research today on a Russian campaign running since 22 July against US and European government, telecommunications, financial, hospitality and aerospace targets. The vulnerability is CVE-2026-42897, an 8.1 cross-site scripting flaw in Outlook Web Access that Microsoft has flagged as exploited as far back as May.
The actor is tracked as Laundry Bear, also TA488, Void Blizzard, CL-STA-1114 and UNK_PitStop — the same crew recently tied to a zero-day XSS in Zimbra's Classic UI. They have a type: webmail, cross-site scripting, and the browser as the execution environment.
Two things about this campaign are worth your evening. Only one of them is the exploit.
The half-click
The delivery is what the researchers call a half-click. Opening the email is enough. Not clicking a link, not enabling macros, not opening an attachment — rendering the message in the webmail client triggers the chain.
That erases the last piece of advice most security-awareness programmes still lean on. "Don't click suspicious links" assumes a click exists to withhold. Here the user's only mistake is reading their email, which is their job, and which you have spent years training them to do promptly.
The payload at the end is a previously unknown JavaScript implant called OWAReaper, purpose-built to live inside OWA.
The part that actually matters
Here is the sentence from the research that should reorganise your incident-response plan:
The folder-permission grant lived server-side and required deliberate removal from Exchange. Credential rotation and re-imaging did not evict the actor.
Read that against what your runbook says. Suspected mailbox compromise: rotate credentials, revoke sessions, re-image the endpoint, restore from known-good. That sequence is correct, it is what every framework tells you to do, and against this campaign it accomplishes nothing — because the persistence is not a credential and it is not on the endpoint. It is a permission entry sitting in Exchange, granting access to a mailbox folder, and it will still be there after you have finished congratulating yourself on a clean rebuild.
You did the remediation. The actor kept the mailbox.
This is the third time this week
We have now written this shape three times in five days, in three unrelated products, and the repetition is the story.
On Tuesday it was Fortinet: CVE-2025-68686, a 5.3, which is a bypass of the patch designed to evict attackers who had planted symbolic links for persistence. Patch the appliance, and the eviction still fails.
Yesterday it was Ruflo: CVE-2026-59726, where an unauthenticated MCP bridge exposed memory storage among 233 tools. The maintainer fixed it in 24 hours and the poisoned agent memory persists after the fix, because the artifact of that attack is a belief rather than a shell.
Today it is Exchange: the mailbox stays owned through a full credential-and-endpoint remediation.
Three vendors, three mechanisms — a symlink, a memory store, a folder permission. One pattern: the artifact survives the remediation. Our industry measures response in mean-time-to-remediate, and every one of these bugs is designed so that the remediation completes successfully and changes nothing.
The defensive lesson is not "patch faster." It is that closing the door is a different action from evicting the guest, and most runbooks only describe the first one.
What to do tonight
Patch OWA. That is the floor, not the work.
Then, for any mailbox you have ever considered compromised — including ones you closed out as remediated weeks ago — go and enumerate folder-level permissions in Exchange. Not delegate access, not mailbox rules, not forwarding, all of which your existing hunts probably cover. Folder permissions. Look for grants to accounts that have no business holding them, and for grants whose creation you cannot account for.
That hunt is worth running against historical incidents specifically. Microsoft says exploitation goes back to May. If you had an OWA incident in the last three months and closed it after a credential rotation, the honest position is that you do not know whether it is closed.
Then check your webmail more broadly. This crew hit Zimbra with the same class of bug before pivoting to OWA. If you run any browser-rendered mail client exposed to the internet, the XSS-into-persistent-implant path is now a demonstrated technique against at least two of them.
The honest position
We did not find this. Proofpoint did, and published it with attribution and detail. We hold nothing on CVE-2026-42897 in our own feed — no indicators, no first-party sighting, nothing.
What we can add is the pattern across the week, because we have been writing the other two instances of it as they landed, and three independent occurrences in five days is not a coincidence worth ignoring. Persistence that outlives remediation is not a Fortinet quirk or an Exchange quirk. It is what attackers build once defenders get good at the obvious response.
Confidence capped at 95%. Vulnerability details, attribution and campaign timing are from Proofpoint's research and Microsoft's advisory; the cross-week pattern is our own reading, offered as an argument rather than a finding.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=you-rotated-the-credentials-and-re-imaged-the-laptop-the-russians-still-have-the-mailbox




Comments