OWA Access Now Survives Resets and Reimaging

TA488 has moved past one-time mailbox compromise. The attacker now plants access inside OWA’s browser state, so resetting the password or rebuilding the device does not clear the foothold if the user opens webmail again. Proofpoint says the group began this renewed activity on July 22 and is using CVE-2026-42897, a cross-site scripting flaw in Microsoft Exchange OWA, against U.S. and European government, telecom, financial, hospitality, and aerospace targets. The OWAReaper implant runs when a message is opened in the reading pane, then stores itself in OWA/browser storage so it can come back on later sessions. The persistence is the point. The compromise lives at the mailbox session layer, so credential-only cleanup misses the part that keeps restoring access.

Part of the PlainSec briefing for 2026-07-30

Sources