Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Laundry Bear pivots to new exploit days after Zimbra alert | Computer Weekly

By Computer Weekly by By Computer Weekly
July 29, 2026
Home Uncategorized
Share on FacebookShare on Twitter


The emergent Russian advanced persistent threat (APT) actor dubbed Laundry Bear has initiated a new wave of exploitation activity abusing a Microsoft Outlook Web Access (OWA) cross-site scripting (XSS) flaw, mere hours after a National Cyber Security Centre (NCSC) alert directing attention to the group’s abuse of a similar flaw.

On 23 July, a multinational coalition of cyber authorities, including the NCSC and its American partners, detailed Laundry Bear’s novel ‘half-click’ phishing technique – requiring no user interaction beyond opening a tainted email – that leveraged another XSS flaw, CVE-2025-66376, in Zimbra Collaboration Suite (ZCS). The agencies said the exploit had likely been developed with the assistance of an artificial intelligence (AI) model.

But according to a Proofpoint research team – which tracks Laundry Bear as TA488 – approximately 24 hours prior to the NCSC’s disclosure, the group pivoted to the OWA flaw, CVE-2026-42897, a critical issue that arises from the improper neutralisation of input during web page generation.

CVE-2026-42897 was disclosed by Microsoft on 14 May, shortly after May’s Patch Tuesday update, and appeared on the Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue shortly thereafter.

The Proofpoint team, comprising researchers Greg Lesnewich, Stuart del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan and Mark Kelly, said: “On 22 July 2026 – the day prior to Proofpoint’s joint release with the NSA – TA488 initiated a new wave of exploitation abusing … CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyse, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity.

“TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny.

“If the email is opened in Outlook Webmail, the Outlook Exchange server mishandles the HTML from the message and runs arbitrary JavaScript. This executes the payload in the message body, an implant Proofpoint calls OWAReaper,” they said.

The team said OWAReaper was the “most sophisticated” backdoor delivered via such an exploit that Proofpoint had ever observed. An evolution of the ZImReaper payload, with which it shares multiple behavioural and coding overlaps, OWAReaper is notable for a subtle set of persistence mechanisms that enable it to obtain full access to the mailbox of any authenticated user in the same organisation as the initial victim and making it very hard to remove even with credential rotation and full re-imaging of the target’s device.

And even if the affected device is re-imaged, OWAReaper can return by means of a hidden iframe added to messages stored in OWA’s offline IndexedDB message cache. The iframe executes again should the victim open a poisoned email from the cache, thus reinfecting themselves.

Proofpoint said the overall modus operandi – such as the use of half-click XSS exploits, the use of encoded DNS exfiltration, and the focus on email and credential theft – left it pretty confident that Laundry Bear is the driving force behind the OWA campaign.

They said the group had “greatly improved” its opsec measures and was writing more subtle and capable malwares than before. Moreover, its broader targeting of OWA highlights a wider risk to end-user organisations than its ZCS campaign – although this said, Laundry Bear does seem to still be targeting intelligence collection in support of its paymasters’ geopolitical goals.

Proofpoint also noted that there was some evidence to suggest Laundry Bear has been abusing CVE-2026-42897 on a smaller scale as far back as March 2026, which suggests it is feasible the flaw was used as a zero-day.

“If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488,” they said.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Department for Education suffers data breach | Computer Weekly

Department for Education suffers data breach | Computer Weekly

Recommended.

Walmart bets on AI and digital twins to shape its supply chain strategy

Walmart bets on AI and digital twins to shape its supply chain strategy

July 13, 2026
GIGABYTE Advances Gaming Monitor Technologies with AI-optimized Visuals and Automatic OLED Protection

GIGABYTE Advances Gaming Monitor Technologies with AI-optimized Visuals and Automatic OLED Protection

June 8, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio