A Russia-aligned espionage group known as TA488 has reportedly reappeared after months of limited observed activity, using an Outlook Web Access half-click attack to compromise targets. The campaign is aimed at on-premises OWA environments and centers on planting a browser-based implant called OWAReaper.
The reported technique stands out because it does not rely on a full traditional interaction from the victim, making the attack harder to spot and potentially easier to trigger in normal email or webmail use. Once deployed, the implant operates within the browser environment tied to Outlook Web Access, giving attackers a stealthy foothold for espionage activity.
Researchers say the malware’s persistence is a major concern. The implant is described as surviving even after a system is re-imaged, suggesting defenders may not fully remove the threat if they focus only on the infected device and overlook the wider webmail or browser-related components of the intrusion.
The activity is another reminder that organizations still running on-premises Outlook Web Access face ongoing exposure from targeted threat groups. Security teams are likely to review OWA access, browser artifacts and persistence mechanisms closely when investigating suspicious behavior linked to TA488 and similar espionage campaigns.