discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored hackers, Laundry Bear, are exploiting an Exchange Outlook Web Access vulnerability to deliver a sophisticated backdoor called OWAReaper. The hackers are targeting various organizations, including government entities and companies in the telecommuni…

By Ionut Ilascu·Jul 29·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Image: bleepingcomputer.com

Laundry Bear is exploiting a zero-day vulnerability in Exchange OWA to deliver a backdoor called OWAReaper, which allows them to maintain access to a target's mailbox even if their system is restored from a clean image or credentials are rotated.

Why it matters

This story matters because it highlights the ongoing threat of state-sponsored hacking groups, such as Laundry Bear, who are exploiting vulnerabilities in widely used software to gain unauthorized access to sensitive information.

Imagine you're using a web-based email service, and you open an email that looks normal. But, secretly, it's trying to install a backdoor that lets hackers access your email account even if you change your password or reinstall your computer. This is what's happening with the OWAReaper backdoor, which is being used by Russian hackers to steal email addresses, usernames, and Outlook settings.

Analysis

A Sophisticated Backdoor Delivered via Half-Click Exploits

Laundry Bear, a Russian state-sponsored hacking group, has been exploiting an Exchange Outlook Web Access (OWA) vulnerability to deliver a sophisticated backdoor called OWAReaper. This backdoor is the most sophisticated delivered via half-click exploits, and it allows the hackers to maintain access to a target's mailbox even if their system is restored from a clean image or credentials are rotated.

Improper HTML Sanitization Triggers JavaScript Loader

The exploit delivers a backdoor that researchers call OWAReaper and describe as the most sophisticated backdoor delivered via half-click exploits they saw. Analysis revealed a suite of subtle persistence mechanisms and revealed it to be an evolution of the ZimReaper malware observed in the attacks against Zimbra email servers.

Long-Term Persistence Mechanism

The threat actor achieves this through OWAReaper, which checks for installed Outlook add-ins that have ReadWriteMailbox permissions and uses them to steal OAuth tokens through the GetClientAccessToken operation request. It then calls UpdateFolder to grant itself Owner-level permissions to the 'Default' user (a low-permission preset alias in all Microsoft Exchange tenants) on every mail folder. This allows attackers to access the mailbox from any authenticated account within the organization.

Two of Everything

The malware supports two command-and-control (C2) mechanisms for receiving instructions from the attacker. One of them uses GitHub commit messages as the communication channel. Every 24 hours, the malware queries GitHub's Commit Search API for encrypted messages that match a specific format and include the target's email address.

Key points

  • Laundry Bear is exploiting an Exchange OWA zero-day vulnerability to deliver a sophisticated backdoor called OWAReaper.
  • The backdoor allows hackers to maintain access to a target's mailbox even if their system is restored from a clean image or credentials are rotated.
  • The malware supports two command-and-control (C2) mechanisms for receiving instructions from the attacker.
  • The attackers are using GitHub commit messages as a C2 channel, which makes it difficult to track and disrupt their communication.
The Upside

If this development plays out positively, it could lead to increased awareness and vigilance among email users, which might help prevent similar attacks in the future. Additionally, Microsoft's prompt response to the vulnerability could lead to a more secure Exchange OWA platform.

The Downside

The realistic downside risks or failure modes of this development include the potential for widespread exploitation of the OWAReaper backdoor, which could lead to significant data breaches and compromise of sensitive information. Additionally, the use of GitHub commit messages as a C2 channel could make it difficult to track and disrupt the attackers' communication.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityhackingexchangeowabackdoormalware

Author

Ionut Ilascu

Intelligence analysis by

Llama

Published

Jul 29, 2026

Source

bleepingcomputer.com

Share

Topics

securityhackingexchangeowabackdoormalware

Related

More from this desk

Jul 29·bleepingcomputer.com

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco warns of a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, which was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.

Jul 29·bleepingcomputer.com

Anthropic confirms Claude is down worldwide

Anthropic confirms that Claude is down worldwide due to elevated errors across multiple AI models. The disruption is causing requests to fail with a '529 Overloaded' message, including in Claude and tools that rely on its API.

Jul 29·thehackernews.com

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary files from application servers through crafted image uploads. The flaw, tracked as CVE-2026-66066, can expose secrets such as secret_key_base, the Rails master key,…

Jul 29·bleepingcomputer.com

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Health-ISAC warns healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, an extortion gang that conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks.