TA488 Exploits Outlook Web Access Flaw with Half-Click Attack 

TA488 is exploiting a Microsoft Outlook Web Access vulnerability to compromise users through half-click attacks.

Written By
Ken Underhill
Ken Underhill
Jul 30, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Russia-aligned threat actor known as TA488 has launched a new campaign exploiting a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA). 

The campaign demonstrates increasingly sophisticated techniques for compromising organizations through what researchers describe as “half-click” attacks. 

Key takeaways of the TA488 Outlook Web Access attack

  • TA488 is exploiting CVE-2026-42897 in Microsoft Outlook Web Access (OWA) to execute malicious JavaScript when users simply open a specially crafted email.
  • The browser-based OWAReaper implant establishes long-term persistence through Exchange mailbox permission changes, allowing attackers to maintain access even after credential rotation.
  • OWAReaper uses multiple command-and-control (C2) channels, including GitHub commit messages, email, CDNs, and DNS tunneling, to improve resilience and complicate detection.
  • Proofpoint believes the campaign reflects a significant evolution in TA488’s tradecraft and raises the possibility that the vulnerability was exploited as a zero-day before Microsoft’s security update.
  • Organizations should prioritize patching Outlook Web Access, auditing Exchange permissions and OAuth access, strengthening identity controls, and monitoring for browser-based persistence and mailbox abuse.

TA488 exploits Microsoft Outlook Web Access vulnerability CVE-2026-42897 

According to Proofpoint, the campaign began on Jul. 22, 2026, one day before the company and the NSA jointly published research detailing TA488’s previous operations. 

Researchers said the threat actor appears to have quickly evolved its tradecraft. 

The campaign exploits CVE-2026-42897, a XSS vulnerability in OWA that causes the Exchange server to improperly process attacker-controlled HTML, allowing malicious JavaScript to execute automatically when a recipient simply opens the email. 

To encourage recipients to open the message, TA488 uses generic subject lines covering routine business topics such as supply chain metrics, energy markets, tourism indicators, public health, and semiconductor supply chains. 

Proofpoint said the ordinary subject matter is designed to avoid raising suspicion, encouraging users to quickly view the email before dismissing it without reporting it as malicious.

Researchers also observed that the group’s delivery techniques have become considerably more subtle than those used in its previous campaigns targeting Zimbra. 

Advertisement

OWAReaper malware uses Exchange persistence to survive credential rotation 

Successful exploitation deploys a previously undocumented JavaScript implant that Proofpoint has named OWAReaper. 

Rather than installing traditional endpoint malware, OWAReaper operates entirely inside the OWA browser session, allowing the attackers to conduct post-compromise activity without leaving an executable file on the victim’s system.

Once active, the implant immediately removes evidence of the exploit from the email before collecting information about the user’s environment and Outlook configuration. 

It also attempts to capture stored Outlook credentials through browser autofill mechanisms.

Exchange persistence enables long-term mailbox access 

To maintain long-term access, OWAReaper establishes multiple persistence mechanisms designed to survive browser restarts, password resets, and even complete reimaging of the compromised endpoint.

One of the malware’s most notable capabilities is its ability to establish persistence at the Exchange server level rather than relying solely on the compromised device. 

If compatible Outlook add-ins are present, OWAReaper can obtain OAuth access tokens and modify Exchange mailbox permissions by granting Owner access to the Exchange Default user on selected mailbox folders. 

According to Proofpoint, these server-side permission changes allow attackers to retain mailbox access even after credentials are rotated unless the unauthorized Exchange permissions are removed. 

The implant also stores encrypted components in Outlook browser storage and uses cached offline emails to automatically reinfect users if malicious messages are reopened.  

Advertisement

These techniques allow the malware to persist across multiple recovery scenarios while minimizing its visibility on the endpoint.

OWAReaper uses GitHub C2 and DNS tunneling to evade detection 

Proofpoint also found that OWAReaper incorporates multiple command-and-control (C2) channels to improve operational resilience and reduce the likelihood of disruption. 

The implant can retrieve encrypted instructions from specially crafted GitHub commit messages or from attacker-controlled emails delivered directly to the compromised mailbox. 

It also supports several methods for exfiltrating stolen information.

Its primary communication technique disguises outbound traffic as legitimate requests for image assets by routing encrypted data through well-known content delivery networks (CDNs) before forwarding it to attacker-controlled infrastructure. 

If HTTPS communications become unavailable, the malware automatically falls back to DNS tunneling, encrypting and fragmenting stolen data into DNS queries that closely resemble normal network traffic. 

According to Proofpoint, these layered communication methods complicate detection while improving the malware’s resilience during long-term operations.

TA488 expands targeting beyond government and Zimbra 

Proofpoint believes TA488 has substantially advanced both its exploitation capabilities and malware development since its earlier campaigns. 

Researchers also found that infrastructure supporting the operation was established in March 2026, approximately two months before Microsoft released its out-of-band security update for CVE-2026-42897. 

The timing raises the possibility that the group may have been exploiting the vulnerability as a zero-day before the flaw became publicly known.

The campaign also demonstrates an expansion beyond TA488’s earlier focus on Zimbra environments. 

Government and defense organizations remain the group’s primary intelligence collection targets. 

However, it has expanded its operations to include multiple commercial sectors that support critical infrastructure, national security, and strategic supply chains. 

Advertisement

How organizations can reduce risk

Because the attack executes when a malicious email is simply opened in Outlook Web Access, organizations should assume that traditional phishing defenses alone may not prevent compromise.  

  • Apply Microsoft’s security updates for CVE-2026-42897 and verify that all Outlook Web Access deployments are fully patched.
  • Audit Exchange mailbox permissions, Outlook add-ins, and OAuth or Exchange Web Services (EWS) tokens for unauthorized access or excessive privileges.
  • Strengthen identity security by enforcing phishing-resistant MFA, Conditional Access, least privilege, and continuous monitoring for anomalous sign-in activity.
  • Monitor Outlook Web Access environments for suspicious browser activity, mailbox permission changes, and outbound connections associated with command-and-control communications.
  • Reduce unnecessary exposure by restricting internet-facing Outlook Web Access access where possible and limiting access based on trusted devices, locations, or risk signals.
  • Deploy advanced email security controls capable of detecting HTML-based exploits and educate users that simply opening an email may be sufficient to trigger exploitation.
  • Regularly test incident response plans for compromised mailboxes, credential theft, OAuth token abuse, and browser-based persistence scenarios.

While preventing every compromise is unrealistic, limiting persistence, restricting attacker access, and validating recovery capabilities can help reduce operational impact. 

Bottom line

This campaign highlights how attackers are combining application-layer vulnerabilities with identity abuse and server-side persistence to maintain access beyond the initial compromise.

Security teams should validate that Exchange permissions, OAuth access, and other persistence mechanisms have been fully removed to prevent attackers from regaining access after initial containment. 

Attacks like this reinforce the value of applying Zero Trust principles to continuously validate access and enforce least-privilege permissions. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.