August 4, 2026, 7:23 am | Read time: 3 minutes
A new attack method on Outlook Web Access could give attackers long-term access to foreign mailboxes. Security researchers warn of a wave of attacks where even an opened email can become a problem. Particularly critical: Changing the password may not necessarily end the attackers’ access.
Just Viewing the Message Can Be Enough
The method is known as a “half-click exploit.” Users do not need to take any further actions. Simply opening the message in the Outlook web client can be enough for the malware to start.
The emails in question initially appear inconspicuous. They often contain general information on economic topics, supply chains, or tourism. This is intended to prevent recipients from becoming suspicious. According to current findings, the attack is primarily directed against government agencies and companies in the telecommunications, finance, aerospace, and hospitality sectors.
According to security researchers from “Proofpoint,” the suspected Russia-linked hacker group TA488, also known as Void Blizzard or Laundry Bear, has been sending these messages since July 22, 2026.
Malicious Code Hides Within the Email
The security vulnerability CVE-2026-42897 is being exploited. It allows attackers to inject JavaScript code directly into the content of an email. The actual malicious code can even hide in seemingly harmless social media icons within the message.
Once the infection is successful, the backdoor “OWAReaper” becomes active. It operates entirely within Outlook Web Access and leaves no traditional traces on the affected computer. Additionally, it removes the originally used exploit from the email. This is intended to make later analysis of the attack more difficult.
Attention Teams Users: This Message Can Take Over the Entire System
Dangerous Security Vulnerability in Outlook Mail! Microsoft Urgently Recommends an Update
Why a New Password Isn’t Enough
The attack is considered particularly dangerous because access can persist even after a password change. The malware anchors itself in multiple places within the system and expands its permissions within the Exchange environment.
Also of interest: A wrong click on WhatsApp and strangers can control the phone
As Proofpoint explains, OWAReaper uses three different mechanisms for this. One of them works with stolen OAuth tokens. These digital access keys allow applications to access an account on behalf of the user. Additionally, the attackers manipulate mailbox permissions to secure their access at the server level.
Security Researchers See a New Level of Threat
According to the researchers, OWAReaper is based on an older malware called “ZimReaper” but has been significantly further developed. The experts also consider it possible that the vulnerability was already exploited as a zero-day before Microsoft released a patch.
Proofpoint therefore recommends that companies review Exchange permissions, revoke affected OAuth tokens, and monitor suspicious connections to known command and control servers.
The current case also shows that not only attachments or links pose a risk anymore. Even a seemingly harmless email can be enough to compromise a mailbox. Users of Outlook Web Access should therefore install security updates promptly and take unusual activities in their own accounts seriously. Although the current attack is directed against companies, similar methods could also be used against private individuals.