Laundry Bear’s second, stealthier wave
Researchers at Proofpoint say the Russian-linked hacking group known as Laundry Bear didn’t stop with its Zimbra attacks earlier this year. A day before a global alert went out in late July, the same crew was already exploiting a fresh bug in Microsoft Outlook Web Access (OWA).
The finding, published Wednesday, expands the timeline of a campaign that government agencies and cybersecurity firms first flagged on July 23. That initial warning centered on a vulnerability in Zimbra Collaboration Suite’s webmail platform, which Laundry Bear had abused as recently as February.
Now Proofpoint says the group — also tracked as TA488 and Void Blizzard — began targeting OWA users on July 22, the day before the international advisory. The victims: US and European government entities, plus organizations in telecom, finance, hospitality and aerospace.
Half-click exploits and a new implant called OWAReaper
The attack chain relied on “half-click” exploits, meaning that simply opening a malicious email was enough to trigger the infection. No further user action was required.
Proofpoint described the payload as a JavaScript browser-based backdoor it named OWAReaper. The researchers called it “the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing,” citing its suite of subtle persistence mechanisms.
Greg Lesnewich, one of the report’s authors, posted on social media that OWAReaper was “one of the coolest implants we’ve ever examined.”
Zero-day potential
The researchers said it’s “feasible” that Laundry Bear was exploiting the OWA vulnerability as a zero-day — meaning the group had found and weaponized the bug before Microsoft was even aware of it. The flaw, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted remediation guidance in mid-July, months after the group allegedly began laying groundwork for the campaign in March.
An upgrade in tradecraft
Proofpoint assessed that the malware campaign represented “an improvement in the group’s tradecraft and capability.” The goal remained the same as the Zimbra operation: steal emails and account credentials. But the method evolved.
Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. US prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.
The OWAReaper campaign shows that Laundry Bear is adapting its toolkit and expanding its target list. For organizations still running unpatched OWA instances, the window for protection is narrowing.
What comes next
Proofpoint acknowledged that it didn’t have enough time to include the July 22 discovery in its initial alert. The update now gives defenders a fuller picture of the group’s recent activity.
Security teams should prioritize patching both Zimbra and OWA vulnerabilities, monitor for half-click exploit indicators, and review accounts for unusual OWA session behavior. The half-click vector makes traditional user training less effective — the infection starts before the user can make a choice.
Laundry Bear’s persistence and growing sophistication suggest that webmail platforms will remain a prime target for state-backed espionage. The group’s ability to pivot from Zimbra to OWA within months signals a flexible, well-resourced operation.
For now, OWAReaper is the group’s most advanced tool. Whether it’s the last remains an open question.