A Max-Severity Exchange Flaw Lets Kremlin Hackers Backdoor Mailboxes by Opening Email — The Half-Click Has Entered Its Executive Spa Phase

Russian state hackers tracked as TA488, also known as Laundry Bear or Void Blizzard, are exploiting a maximum-severity Microsoft Exchange Server flaw to compromise unpatched environments, according to Ars Technica, citing research from Proofpoint. The vulnerability, CVE-2026-42897, is an OWA cross-site scripting flaw that Microsoft mitigated in May and patched in July. The charming part, if your definition of charming includes dental surgery performed by a spreadsheet, is that the attack can trigger when a target merely opens a malicious email.

🤚 The Open-Palm Inbox Tap

The attack belongs to the miserable little family of “half-click” exploits: the victim does not download a suspicious attachment, run a macro, or type their password into a website called DefinitelyNotRussia.biz. Opening the message in Outlook Web Access can be enough. Proofpoint says the infection chain ends with a custom JavaScript browser implant it calls OWAReaper, purpose-built for persistent access inside OWA.

Ars reports that the vulnerability stems from a failure to properly filter HTML embedded in email, allowing malicious JavaScript execution. That JavaScript then installs a novel browser-based implant. Microsoft assigned the Exchange flaw a maximum severity rating, which is corporate shorthand for “please stop scheduling trust exercises and patch the thing.”

Proofpoint also said TA488 may have exploited the bug as a zero-day. The same actor had recently been tied, along with warnings from Proofpoint and the National Security Agency, to attacks exploiting a flaw in Zimbra. Apparently the group’s strategic vision is simple: if humans insist on reading email, email will be treated as a national vulnerability with formatting.

👐 The Two-Handed Persistence Ritual

The technical details are where the incident becomes less ordinary and more museum-quality awful. OWAReaper executes in the OWA reading pane. It can rewrite the original email on the Exchange server to remove exploit content, disable pop-ups and right-click behavior while it runs, and gather the target’s email address, username, and Outlook settings. This is not smash-and-grab malware; this is a concierge service for unauthorized access.

Ars reports that the implant writes an encrypted version of itself and a decryption wrapper into browser local storage under fields used by OWA’s own rendering and sync flow. In plainer language: it hides inside the furniture and waits for the room to be used normally. Every time the user opens an OWA tab, the legitimate sync process can help bring the implant back to life. Elegant, in the way a trapdoor in a nursery is elegant.

In many cases, Proofpoint said, the backdoor can steal OAuth tokens and gain full mailbox access for authenticated users on the same network. Worse, the access can persist even after password changes and device re-imaging, because the problem is not only on the user’s machine. The server-side state has been made unpleasant. Credential rotation, that beloved sacrament of incident response, becomes a scented candle in a burning data center.

🌿 The Gentle Awakening

This is the part enterprises keep purchasing but never enjoying: identity, browser state, webmail, OAuth, and collaboration tools have merged into one magnificent attack surface. Email used to be a place where bad decisions arrived as attachments. Now it is a runtime environment wearing a suit.

The lesson is not “never use webmail,” because civilization has already chosen convenience and is unlikely to repent before lunch. The lesson is that patch latency has become a leadership metric. If a maximum-severity Exchange flaw has a patch and your organization is still waiting for a maintenance window blessed by six committees, the maintenance window is not risk management. It is decorative procrastination with a calendar invite.

Defenders also need to think beyond passwords. If an attack can persist through credential rotation and endpoint rebuilds, incident response must include server-side cleanup, token revocation, mailbox permission audits, OWA local storage clearing, and monitoring for suspicious outbound connections. The attacker is not politely standing where the antivirus flashlight is pointed.

👑 The Gold-Leaf Reckoning

There is something almost poetic about a state-backed actor weaponizing email rendering, the ancient office ritual by which employees receive newsletters, invoices, and morale damage. TA488 did not need to invent a cinematic cyber weapon. It exploited the place where executives already spend their mornings pretending unread messages are a strategy.

If you run Exchange, the guidance is not glamorous: apply Microsoft’s July patch, review whether Emergency Mitigation Service protections are in place, audit and revoke suspicious tokens and add-ins, examine mailbox permissions, and follow Proofpoint’s cleanup advice for OWA storage artifacts. The crown jewel of security is often not an AI SOC copilot or a dashboard with gradients. It is patching promptly and then verifying that the intruder did not leave a monogrammed robe in the guest room.

The half-click era is an insult to human agency, but a very efficient one. The mailbox has become a lobby, the preview pane has become a door, and the attacker no longer needs you to click. They merely require you to participate in Monday.

“Your email client is now an attack platform with calendar integration.” — The Slap of Wisdom Threat Etiquette Bureau, refusing to open the invitation