Switch language한국어
Back to the list

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

TL;DR AI

Key summary

2 min read
  1. TA488, a Kremlin-aligned hacking group, is exploiting a critical Microsoft Exchange Server XSS flaw to hit unpatched systems.

  2. The campaign installs persistent browser-based malware to steal credentials and sensitive data from Outlook Web Access users.

  3. Microsoft issued mitigation guidance in May and patched the issue in July, while Proofpoint says the flaw may have been used as a zero-day.

  4. The attack chain reportedly ends with a custom implant called OWAReaper.

  5. The activity highlights how a high-severity email flaw can enable stealthy access, credential theft, and broader espionage risk.

Read the original