Your Email Survived the Password Reset. So Did the Hackers.
A Russian state-sponsored group has been planting a backdoor inside Outlook Web Access that survives password resets, credential rotation, and even wiping the victim's device. Here's what business leaders need to know.
Here's a scenario that should keep every business leader up at night: your IT team discovers that an employee's email account has been compromised. They reset the password. They rotate credentials. They wipe the device and rebuild it from scratch. Then they watch, satisfied, as the attacker walks right back in anyway.
This is not a hypothetical. It's exactly what a Russian state-sponsored threat group called Laundry Bear — also tracked as Void Blizzard and TA488 — has been doing since at least March 2026. And their tool for doing it is called OWAReaper.
What Just Happened
On July 22, 2026, enterprise security firm Proofpoint published details of a sophisticated campaign exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Outlook Web Access (OWA) — the browser-based version of Outlook used by organizations running on-premises Exchange servers. Microsoft had previously flagged the vulnerability in May 2026, but evidence suggests Laundry Bear was exploiting it as a zero-day as far back as March 2026, a full two months before Microsoft's out-of-band patch.
The target list is broad and deliberate: U.S. and European government entities, telecommunications companies, financial institutions, hospitality organizations, and aerospace firms. The same group was previously caught exploiting a similar flaw in Zimbra's webmail interface with a tool called ZimReaper. Now they've brought the same playbook to Exchange.
The Attack Works Like This
The victim receives an email. They open it in Outlook Web Access — just like they do hundreds of times a day. They don't click anything. They don't download a file. Simply opening the message in the reading pane is enough.
Hidden inside the email's HTML is a JavaScript loader assembled from fragments buried in the message body and triggered automatically when the message renders. This loader executes OWAReaper, a sophisticated browser-based backdoor designed specifically for persistent access inside OWA.
Here's where it gets alarming. Once OWAReaper is running, it embeds itself in OWA's browser storage so that every time OWA opens a new tab, the malware reloads automatically. It grants itself Owner-level permissions to every mail folder in the account — meaning any authenticated user in the same organization now has full mailbox access. It harvests credentials through invisible form fields. It erases its tracks by rewriting the original email to remove the exploit code.
And then — the detail that has security professionals paying very close attention — OWAReaper survives. Completely resetting the victim's password doesn't remove it. Rotating credentials doesn't remove it. Wiping the victim's device entirely and rebuilding from a clean image doesn't remove it. The backdoor lives in OWA's browser-side storage and on the Exchange server itself. The only way to fully remediate it is a multi-step process that involves cleaning the endpoint, the mail server, and revoking all OAuth tokens — steps that most IT teams aren't equipped to do without expert guidance.
Why This Is Different
Most cyberattacks rely on persistent access through infected devices or compromised credentials. Reset the password, reimage the machine, and you've stopped the bleeding. That playbook — the one every IT department knows — doesn't work here.
OWAReaper doesn't live on the endpoint. It lives inside your email infrastructure. The implications are significant: intercepted communications, stolen credentials, compromised contacts, surveillance of every email conversation going forward. For organizations in finance, healthcare, legal, or government sectors, a persistent mailbox implant is potentially more damaging than ransomware. At least with ransomware, you know you've been hit.
This campaign also speaks to the growing sophistication of nation-state targeting. Laundry Bear is linked to Russian intelligence services. Their targets aren't chosen randomly — they're chosen for intelligence value. If you're in aerospace, defense contracting, financial services, government contracting, or telecommunications, you should assume you are on a targeting list somewhere. Not maybe. Assume.
Three Questions Every Business Leader Must Ask
First: Are you running on-premises Exchange? OWA is the attack surface here. Organizations running fully cloud-hosted Microsoft 365 with no on-premises Exchange exposure are not directly vulnerable to this specific attack chain. But if you're running on-premises Exchange — or a hybrid environment where OWA is accessible — the patch for CVE-2026-42897 is not optional. It should have been applied the day it dropped. If you don't know whether it has been, find out today.
Second: If you discovered a compromised mailbox tomorrow, do you have the capability to fully remediate it? Resetting passwords is not sufficient here. Full remediation requires cleaning the endpoint, removing injected storage on the Exchange server, revoking all active OAuth tokens and delegated permissions, and auditing every mail folder for unexpected Owner-level access grants. Does your IT team know how to do that? Do you have a process written down? If the answer is no, that gap needs to be closed before an incident forces the issue.
Third: Are you monitoring for anomalous mailbox permission changes? The tell-tale sign of OWAReaper compromise is unexpected Owner-level delegate permissions appearing on mail folders. This is not a normal configuration. If you have a SIEM or email security solution, does it alert on this type of permission change? Most don't by default. Adding that detection rule is a low-cost, high-value improvement you can make this week.
The Bigger Picture
This campaign is a reminder that the most sophisticated threat actors aren't kicking in the front door. They're finding the unlocked window — a webmail interface that's been running quietly for years — and building a home inside it.
The response isn't panic. The response is rigor. Patch what needs to be patched. Know your environment. Understand what fully remediated actually means for your organization. And if you're in an industry that a Russian intelligence operation considers worth targeting, treat your email security with the same seriousness you'd give your most sensitive business data.
Because if OWAReaper has taught us anything, it's that your email is your most sensitive business data.
---
TrustPoint Cyber helps organizations in targeted industries assess their email security posture, implement detection for persistent mailbox threats, and build response playbooks that account for nation-state-level persistence techniques. If you're not sure whether your environment is exposed, let's talk.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.