CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6328

As cited

Copy frozen at (site build).

threat intel

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

TA488, a Russian-aligned threat actor, resumed operations using a half-click exploit against Outlook Web Access (OWA) to deploy the OWAReaper implant. The implant persisted across system re-imaging, indicating sophisticated post-compromise capability.

Why it matters: Organizations using OWA face compromise risk from a known persistent threat actor; security teams should audit OWA access logs, review email security controls, and assess whether OWAReaper detection is in place.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary