Security · 1h ago
OWAReaper Exploit Adds Persistence via Email View
Russian threat actor TA488 exploits CVE-2026-42897 in Outlook Web Access, allowing a half-click attack that runs JavaScript when an email is opened. The malware steals credentials and OAuth tokens, and persists in browser and Exchange settings. It grants mailbox access to other accounts, surviving device reimaging.
Meridian48 take
The attack's persistence in Exchange settings, not just the browser, makes it particularly dangerous for enterprises, as traditional endpoint defenses may miss it.
Read the full reporting
TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email →
DEV Community
owareaperta488