Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Russian state hackers from group TA488 are exploiting a critical Microsoft Exchange Server vulnerability to backdoor unpatched machines and steal credentials using a novel JavaScript implant called OWAReaper.
Russian state hackers are exploiting a maximum-severity vulnerability in Microsoft Outlook's Exchange Server to backdoor unpatched machines and steal credentials and confidential information. The attacks originate from TA488, a group working on behalf of the Kremlin, also known as Laundry Bear and Void Blizzard. Proofpoint and the NSA warned that TA488 had been exploiting a zero-day vulnerability in Zimbra email services and is now using the Exchange Server flaw to install advanced malware when a user opens an email in Outlook Web Access (OWA). TA488 employs 'half-click' exploits where opening the email triggers compromise, using improved loading mechanisms and malware. This infection chain ends with a novel JavaScript browser-based implant called OWAReaper, designed for persistent access inside OWA, indicating enhanced tradecraft and capabilities by the group.