Laundry Bear / Void Blizzard Exchange OWA Zero-Day Exploitation (OWAReaper Backdoor)
First seen Jul 30, 2026 · Updated Jul 30, 2026
Russian state-sponsored group Laundry Bear (aka Void Blizzard) is exploiting an unpatched zero-day in Microsoft Exchange Outlook Web Access to gain long-term access to victim mailboxes. The attackers deploy a custom backdoor called OWAReaper to maintain persistent, covert access for intelligence collection and espionage purposes.
Technical Analysis
The threat actor exploits a zero-day vulnerability in Exchange OWA to bypass authentication controls and implant OWAReaper, a custom backdoor enabling persistent mailbox access and likely credential harvesting from webmail sessions. The exact CVE has not yet been publicly assigned or disclosed, indicating active in-the-wild exploitation ahead of a patch. Given OWA's role as an internet-facing authentication surface, this attack vector likely enables lateral movement, credential theft, and interception of sensitive correspondence including API keys, service account credentials, and integration tokens. Organizations that route agent-to-human notifications, approval workflows, or API key provisioning through Exchange/OWA-integrated mailboxes face risk of credential exfiltration that could be leveraged to compromise connected AI agent systems, RAG pipelines, or automated tooling relying on email-based authentication or secrets distribution.
Affected Systems
Microsoft Exchange Server with Outlook Web Access (OWA) enabled, on-premises Exchange deployments exposed to the internet; specific vulnerable versions not yet disclosed by Microsoft
Indicators of Compromise
- OWAReaper backdoor (file name/hash not yet published)
- Associated infrastructure not yet publicly disclosed
Remediation Steps
- 1
Monitor Microsoft Security Advisories
Watch for official CVE assignment and patch release from Microsoft for the Exchange OWA zero-day and apply immediately upon availability.
- 2
Restrict OWA Internet Exposure
Limit or disable external access to OWA where feasible, or place it behind VPN/conditional access policies requiring MFA.
- 3
Hunt for OWAReaper Indicators
Review Exchange server logs, IIS logs, and mailbox audit logs for anomalous authentication patterns, unusual mailbox exports, or unrecognized backdoor processes.
- 4
Rotate Credentials and API Keys
Rotate credentials, service account passwords, and any API keys or secrets that may have been transmitted or stored in compromised mailboxes, especially those used by automated or agentic systems.
- 5
Enable Enhanced Logging and EDR on Exchange Hosts
Deploy endpoint detection and response tooling on Exchange servers and enable verbose logging to detect exploitation attempts and post-compromise activity.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.