Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

0
Medium
Exploitweb
Published: 07/29/2026 (07/29/2026, 23:44:07 UTC)
Source: Bleeping Computer

Description

A Russian state-sponsored group known as Laundry Bear (Void Blizzard) is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to deliver a backdoor named OWAReaper. This exploit is used in targeted email campaigns to gain long-term access to victim mailboxes. The vulnerability and exploit details are not fully disclosed, and no patch information is provided. There is no indication of known exploits in the wild beyond these campaigns.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 23:52:22 UTC

Technical Analysis

The threat involves a zero-day vulnerability in Microsoft Exchange OWA exploited by the Russian hacking group Laundry Bear (Void Blizzard). They use this vulnerability in email campaigns to deploy a sophisticated backdoor called OWAReaper, enabling persistent mailbox access. The exploit targets on-premises Exchange servers, not cloud services. No patch or remediation details are available, and no known widespread exploitation has been reported.

Potential Impact

Successful exploitation allows attackers to maintain long-term unauthorized access to Exchange mailboxes, potentially leading to data theft, espionage, or further network compromise. The backdoor OWAReaper facilitates persistent access, increasing the risk of ongoing compromise.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a zero-day exploit with no known patch, organizations should monitor official Microsoft advisories for updates. Implementing additional email filtering and network monitoring focused on Exchange OWA traffic may help detect exploitation attempts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/","fetched":true,"fetchedAt":"2026-07-29T23:52:17.129Z","wordCount":1237}

Threat ID: 6a6a92319c2644c7f8344126

Added to database: 07/29/2026, 23:52:17 UTC

Last enriched: 07/29/2026, 23:52:22 UTC

Last updated: 07/30/2026, 02:36:56 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses