
A Russian state-sponsored hacking group known as Laundry Bear — also tracked by Microsoft as Void Blizzard — has been running a long-term espionage campaign against government agencies, telecoms, financial institutions, and aerospace companies in the United States and Europe. The group exploited CVE-2026-42897, a now-patched cross-site scripting flaw in Microsoft Exchange’s Outlook Web Access (OWA), to deliver a sophisticated backdoor called OWAReaper through what researchers describe as a “half-click exploit” — meaning a victim only has to open a malicious email in OWA for the attack to succeed, with no link click required.
What makes OWAReaper particularly dangerous is its resilience. Once planted, it manipulates Exchange folder permissions and installs a malicious Outlook add-in that survives credential rotation and even full system reinstallation. The backdoor communicates over two covert channels — GitHub commit messages and email parsing — making it harder to detect through standard network monitoring. Microsoft patched CVE-2026-42897 on May 14, 2026, but researchers now report that Laundry Bear used access gained through this flaw to establish persistence that extends beyond the patch window, and the campaign has claimed additional victims since February.
How to check if you’re affected
Affected versions include any on-premises Microsoft Exchange Server installation that had not applied the May 14, 2026 security update before being targeted. If your organization runs on-premises Exchange, verify the patch is applied and audit for two key indicators of compromise: unexpected changes to mailbox folder permissions, and unfamiliar Outlook add-ins registered on the server. Cloud-hosted Microsoft 365 is not affected by this vulnerability. Organizations in government, telecom, finance, hospitality, or aerospace that received suspicious emails via OWA before May 14 should review Exchange logs with Microsoft’s Detection and Response Team.
