Back to feed
Dev.to
Dev.to
7/31/2026
TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

Short summary

Proofpoint details TA488's OWAReaper exploit (CVE-2026-42897), a half-click attack where simply opening a crafted email in Outlook Web Access executes JavaScript that steals credentials, OAuth tokens, and mailbox permissions. The implant hides inside OWA settings and IndexedDB, persists server-side via folder ACL changes, and uses GitHub commit messages for C2 — surviving device reimaging and password resets. Detection requires monitoring folder permission changes, OWA setting modifications, GitHub API traffic, and unusual email API activity.

  • Opening a crafted email in OWA triggers CVE-2026-42897, executing JavaScript that steals credentials and OAuth tokens with no file traces on the endpoint
  • Persistence lives server-side in Exchange mailbox permissions and OWA settings, surviving device reimaging and password changes
  • Detection requires auditing folder ACL changes, OWA settings, GitHub API traffic, and disabling browser autofill and unnecessary mailbox add-ins

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more