Skip to content
feed: live
>_ 0dayNews
microsoft

Void Blizzard Deploys OWAReaper via Exchange Zero-Day

Russia-linked Laundry Bear is exploiting an Exchange OWA zero-day to install OWAReaper, a backdoor giving attackers persistent access to victim mailboxes.

Void Blizzard Deploys OWAReaper via Exchange Zero-Day
Photo: Altostratus / Wikimedia Commons · CC BY-SA 4.0
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

The Russian state-sponsored group tracked as Laundry Bear — also catalogued by Microsoft as Void Blizzard — is exploiting a zero-day vulnerability in Exchange Outlook Web Access to deploy a backdoor called OWAReaper, BleepingComputer reported Tuesday. The objective, per the report, is durable, low-profile access to victim mailboxes — the kind of collection operation that takes weeks to surface if you catch it at all.

No CVE has been publicly assigned at the time of publication.

The actor

Laundry Bear, tracked by Microsoft’s threat intelligence unit as Void Blizzard, is assessed to operate in support of Russian state intelligence objectives. The group focuses on credential theft and persistent access to high-value communications infrastructure. Email servers are a recurring target for exactly the reason you’d expect: everything flows through them — executive discussions, legal threads, merger negotiations, internal security reviews. Planting a foothold in OWA gets you mail collection without the lateral movement that lights up endpoint telemetry.

The technique

According to BleepingComputer, the attack chain uses email campaigns to reach targets, then exploits a vulnerability in the Exchange OWA interface to deliver and install OWAReaper. The specific technical mechanics of the OWA flaw have not been publicly disclosed, which is the appropriate posture while vendor remediation is underway.

Operating at the OWA layer is a notable choice. It keeps the implant close to the mail store without requiring the same level of internal network traversal as a conventional endpoint payload. For defenders, that distinction matters: your EDR coverage of endpoints won’t see an implant that lives in the web front-end tier.

What to check now

If you’re running Exchange on-premises with OWA internet-accessible — still common in hybrid configurations — this warrants attention before Microsoft issues a patch:

  • Watch for Microsoft’s security advisory for this flaw and prioritize it when it drops.
  • Review OWA authentication logs for anomalous patterns: logins from unexpected IP ranges, off-hours access, or credential use that shouldn’t be touching OWA.
  • Evaluate whether OWA needs to be directly internet-reachable or whether it can be placed behind a VPN or access proxy in the interim.
  • When OWAReaper indicators of compromise become available through Microsoft MSTIC or the reporting researchers, run them against your environment.

The pattern

Exchange keeps appearing on this list. ProxyLogon (CVE-2021-26855) in 2021, ProxyShell (CVE-2021-34473) that same summer, the OWASSRF campaign in late 2022 — and a steady supply of OWA-adjacent advisories in the years since. On-premises Exchange is one of the most consistently targeted surfaces in enterprise IT: highly privileged, often internet-accessible, and, because mail cannot simply go offline, frequently subject to patch delays that wouldn’t be tolerated elsewhere in the stack.

That calculus hasn’t changed. It probably won’t until the last on-prem Exchange instance migrates somewhere else, and that migration is not happening on a timetable that helps anyone this week.

Developing. Source: BleepingComputer. No CVE publicly assigned at time of publication. This story will be updated as Microsoft releases official guidance.

Found this useful? Share it.