BTC$63,083+0.50% LTC$44.11+1.19% XMR$409.26+2.83%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Jul 29, 2026 · 2 min read · Original story

Laundry Bear’s webmail hackers had more in store after February, report says

Laundry Bear’s webmail hackers had more in store after February, report says
Laundry Bear’s webmail hackers had more in store after February, report says

Researchers say the Russian state-linked hacking group tracked as Laundry Bear has been more active in recent months than originally thought.

Government agencies and cybersecurity companies warned on July 23 that the cyber-espionage group was abusing a vulnerability in Zimbra Collaboration Suite’s webmail platform. On Wednesday, researchers at Proofpoint issued an update saying that the same hackers began exploiting a bug in Microsoft Outlook Web Access (OWA) a day before the international alert.

Laundry Bear targeted “US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors,” the researchers said. The goal, as with the campaign against Zimbra users, was to steal emails and account credentials.

The malware campaign represented “an improvement in the group’s tradecraft and capability,” Proofpoint said. The company said it had not seen any activity by the group between February and July 22.

“This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA,” the researchers said, adding that it’s “feasible” that Laundry Bear was exploiting the vulnerability as a zero-day.

Laundry Bear compromised accounts with “half-click” exploits, meaning that simply opening an email was enough to begin the infection chain, Proofpoint said.

OWAReaper itself “is the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing, primarily due to its suite of subtle persistence mechanisms,” the researchers said. Greg Lesnewich, one of the report’s authors, said on social media that it was “one of the coolest implants we’ve ever examined.”

Laundry Bear, also tracked as TA488 and Void Blizzard, started laying the groundwork for the OWAReaper campaign in March, Proofpoint said. The OWA bug, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted additional remediation information in mid-July.

Proofpoint said it did not have sufficient time to analyze and include the July 22 discovery into its alert last week.

Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. U.S. prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.

References in this story

  1. International alert spotlights Russia-linked attacks on Zimbra webmail therecord.media A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
  2. Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US www.proofpoint.com Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
  3. Greg Lesnewich (@greg-l.bsky.social) bsky.app So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants…
  4. NVD - CVE-2026-42897 nvd.nist.gov
  5. Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub techcommunity.microsoft.com We have released Security Updates for Exchange Server SE. Exchange Server 2019 and 2016 ESU updates only.  
  6. Dutch intelligence unmasks previously unknown Russian hacking group 'Laundry Bear' therecord.media Recent attacks on institutions in the Netherlands were the work of a previously unknown Russian hacking group that Dutch intelligence agencies are labeling Laundry Bear. Microsoft also reported on the group, naming it…
  7. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
  8. Joe Warminsky (@jwarminsky.bsky.social) bsky.app News Editor at The Record: @therecordmedia.bsky.social [ Tired of bios ] [ Often thinking about music ] [ Etc. ]

Guides related to this story

← Back to all news