CISOOnline

Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover

“TA488 used intentionally vague message lures with no call-to-action for the targeted user,” Proofpoint said. The messages resembled routine informational updates, including material on supply chains and market indicators. Opening one in OWA triggered OWAReaper, a previously undocumented JavaScript implant that runs inside the reading pane.

OWAReaper removes the exploit code from the message stored on the Exchange server after execution, reducing the evidence visible to users and investigators. It can collect account information and attempt to capture credentials entered through browser autofill.

If OWAReaper finds an Outlook add-in with ReadWriteMailbox permissions, it can use the add-in to obtain an OAuth token and grant owner-level access to Exchange’s built-in “Default” identity. This could allow an attacker controlling another authenticated account in the organization to continue accessing the victim’s mail folders.



Source link