Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

OWAReaper: A Sophisticated Backdoor Exploiting Microsoft Exchange Server Vulnerability


Microsoft Exchange Server Vulnerability Exploited by Kremlin Hackers: A Sophisticated Backdoor Named OWAReaper

  • A severe vulnerability in Microsoft's Exchange Server is being actively exploited by Kremlin hackers.
  • The vulnerability, CVE-2026-42897, allows attackers to install a sophisticated backdoor known as OWAReaper.
  • OWAReaper can gain persistent access to unpatched machines and steal credentials, email addresses, and other confidential information.
  • The attack is linked to TA488, a group working on behalf of the Kremlin, which uses OWAReaper to install advanced malware.
  • Users are advised to revoke Exchange Web Services tokens for unauthorized add-ins, remove folder permissions, clear local storage key, and block suspicious connections.


  • Ars Technica has sounded the alarm on a severe vulnerability in Microsoft's Exchange Server, which is being actively exploited by Kremlin hackers to install a sophisticated backdoor known as OWAReaper. This malicious software allows attackers to gain persistent access to unpatched machines and steal credentials, email addresses, and other confidential information.

    The vulnerability, tracked as CVE-2026-42897, is a cross-site-scripting (XSS) vulnerability that stems from a failure to properly filter HTML embedded in an email. Microsoft provided mitigation advice for this vulnerability in May and patched it in July, but hackers have been quick to exploit the zero-day vulnerability.

    Proofpoint researchers have warned that TA488, a group working on behalf of the Kremlin, is using OWAReaper to install advanced malware when a user opens an email sent to an Outlook Web Access (OWA) account. The malicious JavaScript installs a novel browser extension that gives attackers persistent access to victims' OWA accounts.

    The OWAReaper backdoor executes entirely in the Outlook Web Access reading pane and uses Outlook APIs to rewrite the email on the Exchange server and remove exploit content. It disables OWA pop-ups and right-click ability while it runs, then creates a session key unique to each target and gathers the user's OWA saved credentials.

    OWAReaper then writes an encrypted version of itself and a decryption wrapper into the browser's localStorage under settings fields in the PageDataPayload.OwaUserDefaultSettings key. This legitimate key is used by OWA in its page rendering, where OWA evaluates OwaFrontendSyncState as part of its own sync restore flow.

    The backdoor can go on to steal OAuth tokens and gain full access to the mailbox of any authenticated user on the same network. However, it's unclear if machines compromised by OWAReaper are disinfected once Microsoft's July patch or a separate Exchange Emergency Mitigation service is installed.

    To mitigate this vulnerability, Proofpoint advises affected users to revoke and audit their Exchange Web Services tokens for unauthorized add-ins, remove folder permissions to default users, clear the OWA indexDB and PageDataPayload.owaUserDefaultSettings local storage key, and block or alert when machines make outbound connections to command-and-control servers at asecdns[.]com, acocdn[.]com, dnsrecursive[.]eu, and tdndns[.]com.

    This attack highlights the importance of keeping software up-to-date and being cautious when opening emails from unknown senders. As TA488 continues to exploit this vulnerability, it's essential for users to take proactive steps to protect themselves against sophisticated backdoors like OWAReaper.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/OWAReaper-A-Sophisticated-Backdoor-Exploiting-Microsoft-Exchange-Server-Vulnerability-ehn.shtml

  • https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-42897

  • https://www.cvedetails.com/cve/CVE-2026-42897/


  • Published: Fri Jul 31 10:30:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us