supply-chaintrade-pressNewsThe Broadside1 min read

Laundry Bear shifted to Outlook Web Access before July alert dropped

Proofpoint found the group exploiting a Microsoft OWA vulnerability the day before CISA's international advisory on its Zimbra campaign, extending the timeline past February.


TL;DR

Russian state-linked group Laundry Bear began exploiting a Microsoft Outlook Web Access vulnerability on July 22, the day before CISA and international partners warned of the group's Zimbra webmail campaign. Proofpoint researchers said the OWA operation targeted U.S. and European government entities and the telecom, financial, hospitality, and aerospace sectors, deploying a novel JavaScript backdoor called OWAReaper. The implant used "half-click" exploits: opening a crafted email triggered the infection chain. Microsoft patched the underlying bug, CVE-2026-42897, in May and posted remediation guidance in mid-July.

Proofpoint published findings Wednesday showing Laundry Bear (also tracked as TA488 and Void Blizzard) had already moved on from Zimbra by the time the international advisory landed. On July 22, the day before CISA, the NSA, the FBI, and partner agencies from the U.K., Europe, Australia, and New Zealand issued their alert on the group's Zimbra Collaboration Suite exploitation, Proofpoint observed Laundry Bear exploiting a separate vulnerability in Microsoft Outlook Web Access.

The timing means the advisory described a campaign whose operational window had already closed. The Zimbra activity ran through February; the OWA groundwork started in March.

The OWA campaign represents what Proofpoint called "an improvement in the group's tradecraft and capability." The infection chain used "half-click" exploits, opening a crafted email in OWA was sufficient to begin compromise. The payload, OWAReaper, is a JavaScript browser-based implant researchers described as the most sophisticated backdoor they had seen delivered via that technique, citing "a suite of subtle persistence mechanisms."

Microsoft patched the underlying flaw, CVE-2026-42897, in May and published remediation information in mid-July. Proofpoint said it had insufficient time to analyze the July 22 discovery for inclusion in last week's international advisory.

The targeting scope matched the Zimbra campaign's ambition: U.S. and European government entities plus telecom, financial, hospitality, and aerospace sectors. Espionage remained the objective, credential and mailbox theft at scale.


Published ·Deep Fathom

Laundry Bear shifted to Outlook Web Access before July alert dropped — The Broadside