Home / Uncategorized / Russian spies move their «half-click» attack from Zimbra to Outlook: the email that infects just by opening it

Russian spies move their «half-click» attack from Zimbra to Outlook: the email that infects just by opening it

Russian spies move their «half-click» attack from Zimbra to Outlook: the email that infects just by opening it

Russian espionage groups have once again shown that email remains one of the most dangerous attack surfaces. Proofpoint has detected that the TA488 grouping, also known as «Laundry Bear», has moved its sophisticated «half-click» attack from Zimbra Collaboration Suite to Outlook Web Access (OWA), the web interface of Exchange Server. The campaign, targeting governments and companies in the U.S. and Europe, exploits vulnerability CVE-2026-42897, a cross-site scripting (XSS) flaw that allows malicious code to run in the victim’s browser with a single condition: opening the message.

What the «half-click» attack is

The name «half-click» perfectly describes the mechanics of the attack. In traditional phishing, the attacker needs the victim to click a link, open an attachment, or enter their credentials on a fake page. With this technique, that intermediate step almost completely disappears: the user only has to open the tampered email in OWA for the browser to execute the JavaScript controlled by the attackers inside the authenticated email session. There are no suspicious links to review or attachments to distrust, turning the very act of reading the email into the trigger of the infection.

The group began exploiting the vulnerability in OWA one day before researchers and government agencies exposed its abuse of a zero-day in Zimbra Collaboration Suite, suggesting a coordinated and well-resourced operation. It is important to note that Exchange Online, the cloud version of the service, is not affected by this particular flaw: the target is on-premises Exchange Server environments, the ones that organizations manage on their own servers.

OWAReaper: an implant that lives in the mailbox

The most unsettling aspect of the campaign is the implant that the attackers deploy. Dubbed OWAReaper, this browser malware resides entirely within OWA, so it barely leaves traces on the victim’s operating system. According to Proofpoint’s analysis, the implant communicates with two independent command-and-control channels, supports multiple data exfiltration methods and, most concerning of all, survives browser restarts, password changes, and even a complete device rebuild.

The reason is simple: the foothold is not on the user’s hard drive, but in the compromised mailbox itself. Every time the victim accesses their email from OWA, the implant loads again. For many organizations, changing the password or reinstalling the device was the standard response to a possible intrusion; with OWAReaper, that measure is no longer effective, and cleanup requires locating and removing the malicious content within the mailbox itself and the Exchange infrastructure.

A broad campaign designed to go unnoticed

TA488 is not a new group in the espionage landscape. Researchers have been tracking it for a long time and link it to Russian intelligence interests, with a clear priority on gathering information against governments and the defense sector. However, this campaign has a peculiarity: an unusually wide range of victims that includes public administrations in the U.S. and Europe, as well as telecommunications, financial services, hospitality, and aerospace companies.

Proofpoint believes this spread is deliberate. By blending in with the background noise of everyday email traffic, the malicious communications become much harder to detect than the surgical operations typical of espionage groups. The lures used are generic and unremarkable: messages that look routine and that the recipient opens and glances over without giving them importance, exactly the behavior the attackers need.

A zero-day that may have been active since March

The severity of the case increases when analyzing the timeline. Microsoft disclosed vulnerability CVE-2026-42897 in May, after exploitations were detected in the wild, and released an out-of-band patch. But Proofpoint estimates that TA488’s attack infrastructure dates back to March, roughly two months before defenders even knew the flaw existed. If that assessment is correct, the campaign had been running for months while the exploit worked as a true zero-day.

For researchers, this evolution reflects a leap in capabilities: the group is not merely recycling a technique that already worked against Zimbra, but perfecting it against a harder target, with simultaneous improvements to the malware and the exploit. The conclusion is uncomfortable for security teams: one of the oldest pieces of advice in cybersecurity, «don’t click on suspicious links», is no longer enough when the simple act of opening an email can compromise an organization.

What organizations can do

The first recommendation is clear: apply Microsoft’s patch for CVE-2026-42897 immediately on any on-premises Exchange Server instance, and verify that there are no internet-exposed OWA instances left unpatched. Monitoring OWA web sessions, reviewing unusual mailbox rules, and inspecting the persistent content inside mailboxes are necessary steps in the face of a possible implant such as OWAReaper. In addition, it is worth assuming that a password change, although essential, does not eliminate an infection that resides in the mailbox itself.

The TA488 campaign confirms a trend that experts have been announcing for years: email will remain the preferred entry vector for intelligence services, and techniques evolve to require less and less victim interaction. Training in detecting these threats, keeping infrastructure patched, and not relying solely on user common sense are the only real defenses against an attack that is triggered by a simple «half-click».