OWAReaper is a browser-resident JavaScript backdoor used by the Russia-aligned cyberespionage group TA488, also known as Void Blizzard and Laundry Bear. It is an evolution of the group’s ZimReaper implant and operates within authenticated on-premises Microsoft Outlook Web Access sessions rather than deploying conventional endpoint files. It has been delivered through half-click exploitation of CVE-2026-42897, a stored cross-site scripting vulnerability in Outlook Web Access: opening a crafted email in a vulnerable session executes the implant without requiring a link click, attachment, or macro.
OWAReaper collects mailbox metadata, user identity and Outlook configuration information, and attempts to capture browser-autofilled credentials through hidden form elements. It identifies Outlook add-ins with ReadWriteMailbox permissions and can abuse them to acquire OAuth access tokens. The implant can modify Exchange folder permissions to grant Owner access to the built-in Default user, creating server-side mailbox persistence that can remain after password resets or device reimaging. Additional persistence is achieved through OWA browser storage and poisoned offline message-cache content, enabling re-execution in new OWA sessions or when cached messages are reopened.
The backdoor removes exploit material by rewriting the initially compromised email, receives encrypted commands through public GitHub commit messages and specially formatted inbound email, and supports toolkit replacement, command-and-control rotation, and arbitrary JavaScript execution. It exfiltrates encrypted information over HTTPS through image-content delivery services and can use DNS tunneling as a fallback. Observed targeting included government entities in the United States and Europe and organizations in telecommunications, finance, hospitality, and aerospace.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-42897 is described as a high-severity (CVSS 8.1) stored XSS vulnerability in on-premises Microsoft Exchange Server Outlook Web Access (OWA). Malicious email HTML is rendered into the authenticated DOM without adequately neutralizing JavaScript event handlers; opening the email in OWA triggers the attack. | OWAReaper est un implant JavaScript résident en mémoire navigateur, évolution du ZimReaper ciblant précédemment Zimbra.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OWAReaper est un implant JavaScript résident en mémoire navigateur, évolution du ZimReaper ciblant précédemment Zimbra.
TA458 and Void Blizzard exploited the “Half-click” vulnerability in Zimbra, Outlook Web Access, Roundcube, and SOGo to use ZimReaper and OWAReaper to collect credentials, contacts, and emails, and establish long-term persistence.
The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client.
The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
T1189 — Drive-by Compromise (Initial Access) ... L’attaque ne nécessite qu’une seule action de la victime : ouvrir l’email dans OWA.
“TA488 delivers a specially crafted HTML email to an internet-facing Outlook Web Access (OWA) mailbox.”
It periodically searches GitHub commit messages for encrypted commands containing the victim's email address and can also receive commands through specially formatted emails stored in OWA's cache.
T1059.007 — Command and Scripting Interpreter: JavaScript ... réception et exécution de modules JavaScript chiffrés.
Le payload JavaScript malveillant est dissimulé dans des fragments d’URL d’images ... encodé en Base64.
Auto-nettoyage : réécriture de l’email compromis via les API Outlook pour effacer les artefacts.
Vol de tokens OAuth : abus de GetClientAccessToken() sur les add-ins avec permission ReadWriteMailbox.
T1552.001 — Unsecured Credentials: Credentials In Files (Credential Access).
It can collect the victim's email address, username and Outlook configuration, while also attempting to capture credentials by creating invisible DOM elements that allow the browser's autofill mechanism to populate usernames and passwords.
For data theft, OWAReaper primarily uses HTTPS with encrypted URI paths that can be routed through image CDN services.
HTTPS primaire : données chiffrées AES-CTR routées via des CDN d’images légitimes ... vers acocdn[.]com.
GitHub Commit Search API : interrogé toutes les 24h, commandes AES-CTR chiffrées.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant JavaScript for Outlook Web Access that performs mailbox and account reconnaissance, captures browser-autofilled credentials, steals OAuth tokens, modifies Exchange folder permissions for persistence, receives encrypted JavaScript command modules, and exfiltrates data over HTTPS or DNS tunneling. It also removes artifacts by rewriting the compromised email.
Credential and email collection malware used to harvest credentials, contacts, and emails and maintain persistence in webmail environments.
A browser-based backdoor that operates within Outlook Web Access (OWA) to maintain persistent access to victims' mailboxes. It collects mailbox and configuration data, attempts credential capture via browser autofill abuse, obtains OAuth tokens through Outlook add-ins, modifies Exchange folder permissions for server-side persistence, re-executes via poisoned offline cache content, and supports C2 and exfiltration over HTTPS, direct server fallback, and DNS.
Malware deployed by TA488 following exploitation of CVE-2026-42897.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.