Researchers say the Russian state-linked hacking group tracked as Laundry Bear has been more active in recent months than originally thought.
Government agencies and cybersecurity companies warned on July 23 that the cyber-espionage group was abusing a vulnerability in Zimbra Collaboration Suite’s webmail platform. On Wednesday, researchers at Proofpoint issued an update saying that the same hackers began exploiting a bug in Microsoft Outlook Web Access (OWA) a day before the international alert.
Laundry Bear targeted “US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors,” the researchers said. The goal, as with the campaign against Zimbra users, was to steal emails and account credentials.
The malware campaign represented “an improvement in the group’s tradecraft and capability,” Proofpoint said. The company said it had not seen any activity by the group between February and July 22.
“This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA,” the researchers said, adding that it’s “feasible” that Laundry Bear was exploiting the vulnerability as a zero-day.
Laundry Bear compromised accounts with “half-click” exploits, meaning that simply opening an email was enough to begin the infection chain, Proofpoint said.
OWAReaper itself “is the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing, primarily due to its suite of subtle persistence mechanisms,” the researchers said. Greg Lesnewich, one of the report’s authors, said on social media that it was “one of the coolest implants we’ve ever examined.”
Laundry Bear, also tracked as TA488 and Void Blizzard, started laying the groundwork for the OWAReaper campaign in March, Proofpoint said. The OWA bug, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted additional remediation information in mid-July.
Proofpoint said it did not have sufficient time to analyze and include the July 22 discovery into its alert last week.
Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. U.S. prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.
Recorded Future
Intelligence Cloud.
Click Here For The Original Source.
