Date: 07/30/2026
Severity: High
Summary
TA488 (Void Blizzard/Laundry Bear) exploited CVE-2026-42897, an Outlook Web Access (OWA) XSS vulnerability, on 22 July 2026. The campaign targeted government, telecommunications, financial, hospitality, and aerospace organizations across the US and Europe. The group used improved “half-click” attacks, where simply opening a malicious email can lead to compromise. The infection chain deployed a new browser-based JavaScript implant called OWAReaper for persistent access within OWA. OWAReaper operates entirely in the browser, leaving no host footprint while supporting covert command-and-control and data theft. Campaign infrastructure was active as early as March 2026, suggesting TA488 may have used the flaw as a zero-day before Microsoft released a patch.
Indicators of Compromise (IOC) List
Domains/URLs | asecdns.com acocdn.com dnsrecursive.eu tdndns.com |
Hash | 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "asecdns.com" or url like "asecdns.com" or siteurl like "asecdns.com" or domainname like "tdndns.com" or url like "tdndns.com" or siteurl like "tdndns.com" or domainname like "dnsrecursive.eu" or url like "dnsrecursive.eu" or siteurl like "dnsrecursive.eu" or domainname like "acocdn.com" or url like "acocdn.com" or siteurl like "acocdn.com" |
Detection Query 2 : | sha256hash IN ("6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4")
|
Reference:
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit