Skip to content
logo The magazine for digital lifestyle and entertainment
CoBi Data protection Fraud Microsoft News Security All topics
Experts Warn

These Emails Can Be Dangerous Without a Click

A smartphone is held against a blue-lit background featuring the Outlook logo. The display shows the Outlook app icon, which includes a blue envelope and a white "O." In the background, the word "Outlook" is blurred.
According to researchers, the OWAReaper malware leaves no traditional traces on affected computers. Photo: Getty Images
Share article

August 4, 2026, 7:23 am | Read time: 3 minutes

A new attack method on Outlook Web Access could give attackers long-term access to foreign mailboxes. Security researchers warn of a wave of attacks where even an opened email can become a problem. Particularly critical: Changing the password may not necessarily end the attackers’ access.

Just Viewing the Message Can Be Enough

The method is known as a “half-click exploit.” Users do not need to take any further actions. Simply opening the message in the Outlook web client can be enough for the malware to start.

The emails in question initially appear inconspicuous. They often contain general information on economic topics, supply chains, or tourism. This is intended to prevent recipients from becoming suspicious. According to current findings, the attack is primarily directed against government agencies and companies in the telecommunications, finance, aerospace, and hospitality sectors.

According to security researchers from “Proofpoint,” the suspected Russia-linked hacker group TA488, also known as Void Blizzard or Laundry Bear, has been sending these messages since July 22, 2026.

Malicious Code Hides Within the Email

The security vulnerability CVE-2026-42897 is being exploited. It allows attackers to inject JavaScript code directly into the content of an email. The actual malicious code can even hide in seemingly harmless social media icons within the message.

Once the infection is successful, the backdoor “OWAReaper” becomes active. It operates entirely within Outlook Web Access and leaves no traditional traces on the affected computer. Additionally, it removes the originally used exploit from the email. This is intended to make later analysis of the attack more difficult.

More on the topic

Why a New Password Isn’t Enough

The attack is considered particularly dangerous because access can persist even after a password change. The malware anchors itself in multiple places within the system and expands its permissions within the Exchange environment.

Also of interest: A wrong click on WhatsApp and strangers can control the phone

As Proofpoint explains, OWAReaper uses three different mechanisms for this. One of them works with stolen OAuth tokens. These digital access keys allow applications to access an account on behalf of the user. Additionally, the attackers manipulate mailbox permissions to secure their access at the server level.

Security Researchers See a New Level of Threat

According to the researchers, OWAReaper is based on an older malware called “ZimReaper” but has been significantly further developed. The experts also consider it possible that the vulnerability was already exploited as a zero-day before Microsoft released a patch.

Proofpoint therefore recommends that companies review Exchange permissions, revoke affected OAuth tokens, and monitor suspicious connections to known command and control servers.

The current case also shows that not only attachments or links pose a risk anymore. Even a seemingly harmless email can be enough to compromise a mailbox. Users of Outlook Web Access should therefore install security updates promptly and take unusual activities in their own accounts seriously. Although the current attack is directed against companies, similar methods could also be used against private individuals.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.