Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

OWAReaper: The Highly Sophisticated Backdoor Exploited by Kremlin Hackers



OWAReaper is a sophisticated backdoor that allows Russian state hackers to gain persistent access to Microsoft Exchange servers by exploiting a maximum-severity vulnerability in Outlook's Exchange Server. The attackers use this backdoor to steal credentials, OAuth tokens, and other confidential information from victims' OWA accounts. Learn more about the threat and how to protect yourself.

  • Ars Technica has warned about a highly sophisticated backdoor called OWAReaper being used by Russian state hackers.
  • The attackers are exploiting a maximum-severity vulnerability in Outlook's Exchange Server (CVE-2026-42897) to gain persistent access.
  • The OWAReaper backdoor can survive even if the victim changes their password or re-images their device, as it writes itself into the browser's localStorage.
  • Proofpoint is advising affected users to take specific steps to prevent unauthorized access.



  • Ars Technica has issued a warning about a highly sophisticated backdoor called OWAReaper, which is being used by Russian state hackers to gain persistent access to unpatched Microsoft Exchange servers. According to security researchers at Proofpoint, the attackers are exploiting a maximum-severity vulnerability in Outlook's Exchange Server, tracked as CVE-2026-42897, which allows malicious JavaScript execution. The vulnerability was patched by Microsoft in July, but it appears that Russian state hackers, working under the group TA488 (also known as Laundry Bear and Void Blizzard), have continued to exploit this vulnerability to install advanced malware.

    The OWAReaper backdoor is designed to work entirely within the Outlook Web Access reading pane and uses Outlook APIs to rewrite emails on the Exchange server, removing any evidence of the initial exploit. It also disables pop-ups and right-click ability while running and gathers the user's email address, username, and Outlook settings. The attackers then use this information to create a session key and gather the user's OWA saved credentials.

    The worst part is that the OWAReaper backdoor can survive even if the victim changes their password or re-images their device, as it writes itself into the browser's localStorage under legitimate keys used by Outlook. This means that once the attackers gain access to a victim's OWA account, they can steal OAuth tokens and gain full access to the mailbox of any authenticated user on the same network.

    Proofpoint is advising affected users to revoke and audit their Exchange Web Services tokens for unauthorized add-ins, remove folder permissions to default users, clear the OWA indexDB and PageDataPayload.owaUserDefaultSettings local storage key, and block or alert when machines make outbound connections to command-and-control servers at asecdns[.]com, acocdn[.]com, dnsrecursive[.]eu, and tdndns[.]com.

    In light of this new threat, it is essential for organizations to ensure that their employees' Microsoft Exchange servers are up-to-date with the latest patches and that they implement robust security measures to prevent such attacks. Additionally, individuals should be cautious when opening emails sent to OWA accounts and verify the authenticity of any requests or attachments.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/OWAReaper-The-Highly-Sophisticated-Backdoor-Exploited-by-Kremlin-Hackers-deh.shtml

  • https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-42897

  • https://www.cvedetails.com/cve/CVE-2026-42897/


  • Published: Mon Aug 10 20:11:15 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us