As cited
Copy frozen at (site build).
threat intel
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488, a Russian-aligned threat actor, resumed operations using a half-click exploit against Outlook Web Access (OWA) to deploy the OWAReaper implant. The implant persisted across system re-imaging, indicating sophisticated post-compromise capability.
Why it matters: Organizations using OWA face compromise risk from a known persistent threat actor; security teams should audit OWA access logs, review email security controls, and assess whether OWAReaper detection is in place.
- Source published
- First seen by Cybersecurity Tracker