Technology

Laundry Bear pivots to new exploit days after Zimbra alert


The emergent Russian superior persistent risk (APT) actor dubbed Laundry Bear has initiated a brand new wave of exploitation exercise abusing a Microsoft Outlook Internet Entry (OWA) cross-site scripting (XSS) flaw, mere hours after a Nationwide Cyber Safety Centre (NCSC) alert directing consideration to the group’s abuse of an identical flaw.

On 23 July, a multinational coalition of cyber authorities, together with the NCSC and its American companions, detailed Laundry Bear’s novel ‘half-click’ phishing approach – requiring no person interplay past opening a tainted e-mail – that leveraged one other XSS flaw, CVE-2025-66376, in Zimbra Collaboration Suite (ZCS). The companies mentioned the exploit had seemingly been developed with the help of a man-made intelligence (AI) mannequin.

However in line with a Proofpoint analysis group – which tracks Laundry Bear as TA488 – roughly 24 hours previous to the NCSC’s disclosure, the group pivoted to the OWA flaw, CVE-2026-42897, a important problem that arises from the improper neutralisation of enter throughout net web page era.

CVE-2026-42897 was disclosed by Microsoft on 14 Could, shortly after Could’s Patch Tuesday replace, and appeared on the Cybersecurity and Infrastructure Safety Company’s (Cisa’s) Recognized Exploited Vulnerabilities (Kev) catalogue shortly thereafter.

The Proofpoint group, comprising researchers Greg Lesnewich, Stuart del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan and Mark Kelly, mentioned: “On 22 July 2026 – the day previous to Proofpoint’s joint launch with the NSA – TA488 initiated a brand new wave of exploitation abusing … CVE-2026-42897, in Outlook Internet Entry (OWA). Proofpoint didn’t have adequate time to analyse, motion, and incorporate the brand new exercise into present reporting, so we’re issuing a speedy follow-up to focus on this exercise.

“TA488 used a sequence of compromised accounts to ship emails exploiting a vulnerability in Outlook Webmail. The marketing campaign focused entities within the authorities, telecommunications, finance, hospitality, and aerospace sectors. The quantity of messages and breadth of concentrating on is uncommon for TA488 and will have been deliberately broad to mix in with mass-mailing spam and keep away from scrutiny.

“If the e-mail is opened in Outlook Webmail, the Outlook Trade server mishandles the HTML from the message and runs arbitrary JavaScript. This executes the payload within the message physique, an implant Proofpoint calls OWAReaper,” they mentioned.

The group mentioned OWAReaper was the “most refined” backdoor delivered through such an exploit that Proofpoint had ever noticed. An evolution of the ZImReaper payload, with which it shares a number of behavioural and coding overlaps, OWAReaper is notable for a refined set of persistence mechanisms that allow it to acquire full entry to the mailbox of any authenticated person in the identical organisation because the preliminary sufferer and making it very exhausting to take away even with credential rotation and full re-imaging of the goal’s system.

And even when the affected system is re-imaged, OWAReaper can return via a hidden iframe added to messages saved in OWA’s offline IndexedDB message cache. The iframe executes once more ought to the sufferer open a poisoned e-mail from the cache, thus reinfecting themselves.

Proofpoint mentioned the general modus operandi – reminiscent of using half-click XSS exploits, using encoded DNS exfiltration, and the give attention to e-mail and credential theft – left it fairly assured that Laundry Bear is the driving drive behind the OWA marketing campaign.

They mentioned the group had “significantly improved” its opsec measures and was writing extra refined and succesful malwares than earlier than. Furthermore, its broader concentrating on of OWA highlights a wider threat to end-user organisations than its ZCS marketing campaign – though this mentioned, Laundry Bear does appear to nonetheless be concentrating on intelligence assortment in help of its paymasters’ geopolitical objectives.

Proofpoint additionally famous that there was some proof to recommend Laundry Bear has been abusing CVE-2026-42897 on a smaller scale way back to March 2026, which suggests it’s possible the flaw was used as a zero-day.

“If so, the mixed enchancment of the malware and the exploit growth towards a more durable goal in Outlook Internet Entry sign a leap in functionality by TA488,” they mentioned.