OWAReaper Backdoor Outlasts Credential Rotation
Updated: OWAReaper maintains Exchange mailbox access after credential rotation. Targeted sectors confirmed: US and EU government, telecom, finance, aerospace.
Updated. The Hacker News reports the OWAReaper backdoor maintains mailbox access after victim organizations rotate their credentials. The standard interim containment step does not clear an already-installed implant.
If your organization acted on Tuesday’s initial reporting by rotating credentials, that action alone is not sufficient.
Updated campaign details
Activity started: July 22, 2026. Confirmed.
Targeted sectors: U.S. and European government entities, telecommunications, financial services, hospitality, aerospace. Single-source as of now — treat as high probability, pending independent corroboration.
Attribution: The same Void Blizzard / Laundry Bear cluster previously exploited a now-patched Zimbra vulnerability. Confidence: high per Microsoft Threat Intelligence.
No CVE assigned for the OWA flaw. No Microsoft patch available at time of publication. The mechanism by which OWAReaper survives credential rotation has not been publicly disclosed — confirmed behavior, unconfirmed mechanics.
Updated priority actions
- Credential rotation is not clearance. OWAReaper is reported to persist independently of user account credentials.
- When Microsoft MSTIC or reporting vendors publish indicators of compromise, audit OWA-side infrastructure — server, web tier, IIS modules — not just user account logs.
- Evaluate whether Exchange OWA requires direct internet exposure. Placing it behind a VPN or access proxy removes the attack surface while patch development continues.
- Watch for Microsoft’s security advisory on the underlying OWA vulnerability.
Developing. Sources: The Hacker News, BleepingComputer. No CVE assigned. No patch available.
Found this useful? Share it.


