View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper

๐Ÿšจ ACTIVE EXPLOITATION

  • Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper Backdoor CVE-2026-42897
    Laundry Bear exploited an Exchange OWA zero-day to gain persistent mailbox access.
    • Targets include U.S. and European government entities and sectors like telecom, finance, hospitality, aerospace
    • Vulnerability CVE-2026-42897 is a cross-site scripting flaw in Outlook Web Access allowing JavaScript execution on email open
    • Attack uses half-click exploit via malicious emails with embedded JavaScript loaders and Base64 payloads
    • Delivers OWAReaper backdoor that steals credentials, modifies mailbox permissions for persistent access
    • Backdoor uses GitHub commit messages and emails for command-and-control and exfiltrates data via encrypted HTTPS and DNS
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Flying Eagle Mobile RAT Builder Emerges as Premium Malware Service in China
    A new mobile RAT builder called Flying Eagle is being used by multiple Chinese threat groups.

    • Targets mobile devices with infostealer malware
    • Used by multiple Chinese threat groups
    • Offers malware-as-a-service for building custom RATs
    • Designed to steal banking credentials and drain accounts
      ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading
  • Astaroth Botnet Adds WhatsApp Web Spambot to Expand LATAM Malware Distribution
    Astaroth operators introduced a WhatsApp Web spambot component to spread malware via social messaging.

    • Targets victims in Latin America, especially Brazil, using localized Portuguese spam templates
    • New spambot automatically messages all contacts in victims' WhatsApp Web contact lists
    • Uses invisible headless browser automation to avoid detection during spam campaigns
    • Shares codebase and tactics with Vareg spambot, linked to previous LATAM banking trojan campaigns
    • Shift from traditional email spam to trusted social messaging platforms for malware distribution
      ๐Ÿ“Ž Coverage: crowdstrike.com ยท ๐Ÿ“„ Original: crowdstrike.com ยท ๐Ÿ‘ via CrowdStrike Blog

๐Ÿ”“ CVEs & KEV

  • CVE-2026-64685 โ€” CVSS 5.3 โ€” ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file c...
  • CVE-2026-62946 โ€” CVSS 5.1 โ€” ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write wh...
  • CVE-2026-62363 โ€” CVSS 5.0 โ€” ImageMagick: Heap Buffer Over-Write in fx operationImageMagick is free and op...
  • CVE-2026-62343 โ€” CVSS 4.7 โ€” ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid k...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check