Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

    Date: 07/30/2026

    Severity: High

    Summary

    TA488 (Void Blizzard/Laundry Bear) exploited CVE-2026-42897, an Outlook Web Access (OWA) XSS vulnerability, on 22 July 2026. The campaign targeted government, telecommunications, financial, hospitality, and aerospace organizations across the US and Europe. The group used improved “half-click” attacks, where simply opening a malicious email can lead to compromise. The infection chain deployed a new browser-based JavaScript implant called OWAReaper for persistent access within OWA. OWAReaper operates entirely in the browser, leaving no host footprint while supporting covert command-and-control and data theft. Campaign infrastructure was active as early as March 2026, suggesting TA488 may have used the flaw as a zero-day before Microsoft released a patch.

    Indicators of Compromise (IOC) List

    Domains/URLs

    asecdns.com

    acocdn.com

    dnsrecursive.eu

    tdndns.com

    Hash  

    6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "asecdns.com" or url like "asecdns.com" or siteurl like "asecdns.com" or domainname like "tdndns.com" or url like "tdndns.com" or siteurl like "tdndns.com" or domainname like "dnsrecursive.eu" or url like "dnsrecursive.eu" or siteurl like "dnsrecursive.eu" or domainname like "acocdn.com" or url like "acocdn.com" or siteurl like "acocdn.com"

    Detection Query 2 :

    sha256hash IN ("6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4")

    Reference:    

    https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit                            


    Tags

    Threat ActorVulnerabilityCVE-2026ExploitZero-dayGovernment Services and FacilitiesCommunicationsFinancial ServicesDefense Industrial BaseTransportation SystemsUnited StatesEuropeStealer

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags