Connect with us

Infosecurity

TA488 Is Back With a Half-Click OWA Attack That Survives Re-Imaging

Published

on

Outlook Web Access attack

A Familiar Threat Actor Breaks Its Silence

After roughly five months of quiet, a Russia-aligned espionage group is back in action. Proofpoint researchers spotted TA488 — also known as Void Blizzard and Laundry Bear — launching a fresh campaign on July 22. That’s one day before the company published a joint advisory with the NSA about the group’s earlier Zimbra activity.

The timing wasn’t accidental. Neither was the target list.

Victims spanned US and European government agencies, plus the telecommunications, financial, hospitality, and aerospace sectors. The volume of messages was unusually high for this group. Proofpoint suspects TA488 deliberately flooded inboxes to blend in with routine spam traffic.

No Click Required: The Half-Click Exploit

The campaign weaponized CVE-2026-42897, a cross-site scripting vulnerability in on-premises Exchange Server. Notably, Exchange Online was not affected.

Here’s the unsettling part: merely opening the email in a vulnerable Outlook Web Access (OWA) client triggered the exploit. The victim’s browser executed embedded JavaScript within their authenticated session. No link clicks. No attachments. No user interaction beyond reading the message.

The lures were deliberately boring. Subject lines referenced semiconductor supply chains, gas markets, and tourism statistics. Proofpoint believes this banality was intentional — recipients would open the email, skim it, decide it was junk, and move on without reporting it. That left no suspicious links or attachments for security teams to investigate.

Why It’s Called a Half-Click

Security researchers use “half-click” to describe attacks that require the victim to open or view content but not actively click anything. In this case, the OWA reading pane did all the work. The exploit fired the moment the email rendered.

OWAReaper: An Implant Built to Endure

The payload is something Proofpoint calls OWAReaper — a previously unknown JavaScript implant that the firm describes as the most sophisticated half-click backdoor it has ever observed. It evolved from ZimReaper, the tool used in TA488’s earlier Zimbra campaigns, but dropped that tool’s mass email exfiltration capability.

OWAReaper runs entirely within the OWA reading pane. There’s no conventional file on disk to detect. Instead, the implant:

  • Rewrites the original email on the server to strip out the exploit
  • Harvests saved credentials from the browser
  • Hides an encrypted copy of itself in browser localStorage under a legitimate OWA settings key
  • Re-executes itself every time the victim opens a new tab

That alone would be bad enough. But the implant’s most durable mechanism lives server-side.

Server-Side Persistence That Outlives the Device

Where mailboxes had add-ins with write permissions, OWAReaper stole OAuth tokens and granted Exchange’s low-privilege Default user Owner-level permissions on every mail folder. The practical effect: any authenticated account in the organization could read those mailboxes.

The implant also planted a hidden iframe in messages stored in OWA’s offline IndexedDB cache. That iframe re-infects the target even after the host machine has been completely re-imaged.

Because the folder-permission grant lives on the server and requires deliberate removal from Exchange, neither credential rotation nor device re-imaging evicts the attacker. The access simply persists.

Two Command Channels, Two Exfiltration Routes

OWAReaper communicates through a pair of command channels. It queries GitHub commit messages daily, and it polls inbound emails every five minutes. That redundancy means the operators have a fallback if one channel gets disrupted.

Data exfiltration happens over HTTPS, proxied through legitimate image content delivery networks. When that fails, the implant falls back to DNS tunneling — a technique that hides data in DNS queries and is notoriously difficult to block.

Timeline Points to Zero-Day Use

The campaign’s infrastructure dates back to March 2026, roughly two months before Microsoft disclosed the flaw. That timeline makes zero-day exploitation feasible, though registration dates alone don’t confirm exactly when the attackers began using the vulnerability.

Microsoft has since released Exchange security updates addressing CVE-2026-42897. Patching is the first line of defense, but Proofpoint warns it’s not enough on its own.

Defenders Need More Than a Patch

Proofpoint urged organizations running on-premises Exchange to go beyond patching. The firm recommends a four-step cleanup:

  1. Revoke Exchange Web Services tokens that may have been compromised
  2. Strip Default-user folder grants from all mailboxes
  3. Clear OWA’s offline IndexedDB database
  4. Delete the malicious localStorage key from affected browsers

Skipping any of these steps could leave the door open. The server-side permission grant, in particular, won’t disappear just because you’ve applied the security update.

This campaign is a reminder that Exchange Server security requires ongoing vigilance, not just quarterly patching cycles. For organizations still running on-premises OWA, the threat landscape just got more complicated.

TA488 has demonstrated it can adapt its tools and return after long silences. The question now is which vulnerability it will target next — and whether defenders will be ready.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

CISA warns of spike in attacks on water systems as Minnesota incidents probed

Published

on

attacks on water systems

CISA issues urgent alert over water utility intrusions

The federal cybersecurity agency is reporting a “significant increase” in malicious activity aimed at water utilities, as investigators are reportedly trying to determine whether recent incidents in Minnesota might be the work of Iran-linked hackers.

The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” PLCs — programmable logic controllers — are at the core of processes in multiple industries.

Multiple news outlets reported that state and federal investigators were working to determine whether disruptions to water systems in Minnesota earlier this month were connected to Iran. Wired magazine reported that a memo from the WaterISAC, the industry’s cybersecurity information-sharing body, said the attacks were tied to Iran.

What happened in Minnesota?

Minnesota’s state IT agency said earlier this week that “more than 30 Minnesota community water systems” were affected by a coordinated cyberattack beginning July 26. The threat actor is “targeting water entities of all sizes,” CISA said.

The intruders “have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses,” CISA said. “This activity has resulted in boil water notices and sustained manual operations.”

CISA, the FBI and the Environmental Protection Agency are all involved in the response. The FBI said “utility companies in at least seven states” have reported incidents involving PLCs to the bureau.

Iran connection remains unclear

At a Cabinet meeting at Camp David on Friday, President Donald Trump placed the blame on Minnesota’s Democratic government. “Iran’s got bigger problems than worrying about Minnesota,” he said.

Earlier this month, CISA updated previous warnings that industrial OT was facing malicious activity linked to Iran. Thursday’s alert does not mention Iran.

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA said. “OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”

Broader context: OT security under siege

Hostilities continued around the Strait of Hormuz on Friday, as oil companies reported massive profits related to the conflict’s effects on energy prices.

This wave of intrusions fits a troubling pattern. Operational technology security has become a prime target for state-sponsored groups, and water utilities — often running on aging infrastructure — are particularly exposed.

For utilities, the immediate takeaway is clear: audit every internet-facing device, including those cellular modems that might have slipped off the radar. Document all external connections. And if you find a PLC exposed, don’t wait — pull it offline.

For more on how cybercriminals are exploiting industrial systems, see our explainer on PLC cyberattack vectors. And for a broader look at how federal agencies are responding, check out CISA’s evolving role in critical infrastructure defense.

Continue Reading

Infosecurity

NCSC Pushes Device Makers to Build Forensic Observability Into Every Network Product

Published

on

Why the NCSC Is Turning Up the Heat on Device Vendors

When a firewall gets compromised, the clock starts ticking. Incident responders need to know exactly what happened, how deep the intrusion goes, and whether the device can ever be trusted again. But too often, that evidence is locked away inside proprietary hardware and software.

The UK’s National Cyber Security Centre (NCSC) has had enough. In a blog post on July 29, Chris A, the agency’s technical director for networking and infrastructure, laid out a clear demand: device manufacturers must embed forensic observability into their products from the ground up.

Firewalls, VPN gateways, and other network appliances are prime targets for attackers. When they fall, organizations are left scrambling. “When incidents occur, organizations need reliable ways to understand what happened and assess whether a device can still be trusted,” Chris A wrote. “This is why forensic observability matters.”

The concept is straightforward: give defenders supported, built-in capabilities to investigate a compromise, rather than forcing them to reverse-engineer the device or hunt for vulnerabilities just to collect basic forensic data. That’s still the norm in many shops, and it’s a costly, time-consuming nightmare.

What Forensic Observability Actually Means

According to the NCSC, forensic observability isn’t a single feature. It’s a bundle of capabilities that should be baked into every network device:

  • Comprehensive telemetry and structured logging
  • Access to configuration state
  • Ability to collect forensic data from memory and data at rest
  • Transparency about the software running on the device, either via version info or a software bill of materials (SBOM)

That last point matters more than most people realize. If you don’t know exactly what software is on a device, you can’t assess its exposure to known vulnerabilities. An SBOM changes that equation entirely.

Chris A emphasized that investigating a compromised device “should not require discovering or exploiting vulnerabilities in the product itself.” Instead, manufacturers should provide supported mechanisms for gathering evidence, assessing impact, and restoring trust in affected systems.

The NCSC isn’t asking for the moon here. “Small design decisions can significantly reduce the time needed to triage and investigate incidents,” he noted.

Three Myths That Hold Vendors Back

The NCSC’s technical director also took aim at misconceptions that keep manufacturers from making these design improvements. These myths, he argued, are preventing progress in network device security.

Myth 1: Observability Helps Attackers

Some vendors worry that exposing telemetry gives attackers a roadmap. The NCSC disagrees. Well-designed features like structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces strengthen security rather than undermine it. Attackers don’t need your logs to exploit your device; they need your vulnerabilities.

Myth 2: Customers Will React Negatively

The fear here is that customers will see forensic features as complexity or backdoors. The reality, per the NCSC, is the opposite. Clear telemetry and forensic capabilities build trust through improved visibility. Buyers want to know what their devices are doing, especially after an incident.

Myth 3: It’s Too Difficult to Build

Yes, forensic observability requires careful engineering. But it’s absolutely achievable, especially when prioritized early in the design process. Waiting until after a product ships makes it exponentially harder — and far more expensive.

What Vendors and Buyers Should Do Now

The NCSC isn’t just publishing blog posts and walking away. The agency released formal guidance on building forensic observability into products back in February 2025. Now it’s pushing vendors to follow it.

Chris A also had a message for IT buyers: push your vendors. If you’re procuring firewalls, VPN gateways, or any other network appliance, ask what forensic capabilities are built in. Demand SBOMs. Make forensic observability a checkbox in your procurement process.

In parallel, the NCSC is working with global partners to develop a reference architecture for forensic observability in network appliances. Once finalized, this should give manufacturers a blueprint for providing “safe, reliable forensic access” without weakening the security of their products.

For incident response teams, this shift can’t come soon enough. The gap between what attackers exploit and what defenders can investigate is a serious problem. Forensic observability closes that gap — but only if vendors actually build it.

Want to dig deeper into related topics? Check out our coverage of Android spyware forensics tools and the broader push for software bill of materials adoption in enterprise security.

Continue Reading

Infosecurity

LogoKit Phishing Kit Now Screenshots Your Real Website to Build Fake Login Pages

Published

on

LogoKit phishing kit

The Hook: A Login Page That Looks Exactly Like Yours

Imagine getting a phishing email that warns your password is about to expire. You click the link. The login page that loads isn’t a generic clone — it’s a real-time screenshot of your company’s actual website, complete with your logo, your branding, even your latest announcements. That’s not hypothetical. That’s what the LogoKit phishing kit is doing right now.

Researchers at Barracuda published findings on July 29 detailing how this phishing-as-a-service platform has evolved. It no longer relies on static templates. Instead, it builds a unique login page for each victim on the fly, pulling live data from commercial web services.

From Brand Impersonation to Environment Impersonation

The shift is subtle but significant. Older phishing kits tried to copy a brand’s look. LogoKit goes further — it recreates parts of the victim’s genuine web environment. Barracuda calls this “environment impersonation.” The page doesn’t just look like the brand; it looks like your specific instance of that brand.

Here’s how it works, step by step:

  1. The phishing URL contains the victim’s email address.
  2. The kit extracts that address and identifies the victim’s employer from the domain.
  3. It calls Clearbit to fetch the company’s official logo.
  4. It uses Thum.io, a commercial screenshot service, to capture a live image of the victim’s actual website.
  5. Additional APIs — Google Favicon, ImageKit, Microlink — load more authentic imagery as the page renders.

The result? A login page that mirrors the real thing down to the pixel. No two victims see the same page.

Legitimate Services Doing the Heavy Lifting

What makes this particularly sneaky is the reliance on reputable third-party services. Thum.io isn’t a malicious tool — it’s a legitimate screenshot API used by developers worldwide. Clearbit is a standard data enrichment service. By piggybacking on these platforms, the kit avoids hosting its own infrastructure.

This isn’t entirely new. RiskIQ first named LogoKit back in 2021, noting it already pulled logos from Clearbit and embedded victim email addresses in URLs. What’s new is the live screenshot element and the scale of customization.

The Lures: Boring but Effective

The bait itself is routine. Barracuda observed campaigns covering password expiry warnings, certificate expirations, access restrictions, delivery failures, timesheet updates, and ICANN verification notices. Nothing exotic — just the everyday anxieties that push people to act fast.

The emails appeared in six languages: English, German, French, Spanish, Chinese, and Korean. That’s a global operation, not a hobbyist experiment.

No Server, No Template, No Signature

Here’s the part that keeps security teams up at night. Credential harvesting doesn’t go to an attacker-controlled backend. It goes to a Telegram bot. After the victim submits their password, they’re redirected to the real website — where they likely assume they mistyped their password the first time. The attacker is already gone with the credentials.

Because there’s no static template, there’s no signature for antivirus or URL filters to fingerprint. Each page is assembled at request time from live data. Blocklisting a domain? Useless. The same problem was flagged with the Starkiller phishing kit back in February, which also bypasses MFA.

How to Defend Against LogoKit and Its Ilk

Barracuda’s recommendations are straightforward but require commitment:

  • Deploy phishing-resistant MFA. FIDO2 security keys and passkeys bind authentication to the legitimate domain. A fake page can’t present the correct cryptographic challenge, so stolen passwords become useless.
  • Use conditional access rules. Restrict logins based on location, device compliance, and risk signals.
  • Consider browser isolation. Render web content in a sandboxed environment so malicious pages never touch the user’s device.
  • Filter URLs aggressively. Flag newly registered domains and links that contain an email address in the path — a telltale sign of this kit.

The bigger lesson? Traditional phishing defenses are crumbling. Static analysis, reputation lists, and user training alone won’t cut it. Attackers have moved to dynamic, per-victim campaigns that look exactly like the real thing. Your defense needs to move just as fast.

For more on how phishing kits are evolving, check out our coverage of phishing kit evasion techniques and MFA bypass attacks.

Continue Reading

Trending