Password resets and device rebuilds do not clear this mailbox foothold. TA488’s OWAReaper leaves a copy of itself in OWA’s browser storage and abuses mailbox permissions and OAuth tokens, so the compromise can come back when the user opens webmail again.
Proofpoint says the group shifted from Zimbra to Microsoft Exchange OWA on July 22 and used CVE-2026-42897, a cross-site scripting flaw, against government, telecom, financial, hospitality, and aerospace targets. Microsoft says the flaw had already been exploited since at least May 2026.
The risk now sits in browser-based email where the attacker can keep reading and manipulating mail from the server side even after the endpoint is cleaned. For mail teams that rely on OWA and OAuth-connected add-ins, the compromise can outlive the original session and the original device.