None
EN
OWAReaper Backdoor Targets Microsoft Exchange Users
['Milan Stanojevic', 'Windows Toubleshooting Expert', 'Milan Has Been Enthusiastic About Technology Ever Since His Childhood Days', "This Led Him To Take Interest In All Pc-Related Technologies. He'S A Pc Enthusiast", 'He Spends Most Of His Time Learning About Computers', 'Technology.', 'Before Joining Windowsreport', 'He Worked As A Front-End Web Developer. Now', "He'S One Of The Troubleshooting Experts In Our Worldwide Team", 'Specializing In Windows Errors']
Windows Report
Russian state-sponsored hackers are exploiting a Microsoft Exchange Outlook Web Access vulnerability to deploy OWAReaper, a webmail backdoor designed for long-term mailbox access.
Attack Exploits CVE-2026-42897The campaign exploits CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access.
Mailbox Permissions Create Server-Side PersistenceThe backdoor can grant Owner-level mailbox permissions to the Exchange Default user across every mail folder.
Changing the user’s password may also fail to block access if the malicious mailbox permissions and stolen OAuth tokens remain active.
OWAReaper creates another persistence mechanism through the Outlook Web Access offline cache.