{
  "Event": {
    "analysis": "1",
    "date": "2026-07-29",
    "extends_uuid": "",
    "info": "[Threat Intel] Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit",
    "protected": false,
    "publish_timestamp": "1785648945",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1785648945",
    "uuid": "f374901a-f9a9-4633-8fea-6e114c064de4",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#2d8ee7",
        "local": false,
        "name": "misp-galaxy:producer=\"Proofpoint\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#72ee33",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#110e53",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DNS - T1071.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3eb869",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Data Staging - T1074.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c8fe6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Email Collection - T1114.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5539fe",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ed4a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#08221e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"",
        "relationship_type": ""
      },
      {
        "colour": "#12d28f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Account - T1087.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#71ecdb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Manipulation - T1098\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#0aebeb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploitation for Client Execution - T1203\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#8d021b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Dead Drop Resolver - T1102.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0add7f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"APT\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#31373d",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"not-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785495621",
        "to_ids": false,
        "type": "link",
        "uuid": "ab55d6a6-d39d-4966-8222-6f2b35b2fcec",
        "value": "https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785495621",
        "to_ids": false,
        "type": "text",
        "uuid": "7f12a663-b495-4a8a-b0f5-2e2557ac3bc1",
        "value": "TA488, a Russia-aligned threat actor, initiated a campaign on July 22, 2026, exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The campaign targeted US and European government entities, along with telecommunications, financial, hospitality, and aerospace sectors. The attack employs half-click exploits requiring only email opening to trigger compromise, delivering OWAReaper, a novel JavaScript browser-based implant designed for persistent OWA access. OWAReaper operates stealthily within the browser context, featuring dual C&C channels via GitHub commit messages and inbound emails, plus HTTP and DNS exfiltration protocols. The implant survives browser reboots, credential rotation, and device re-imaging through multiple persistence mechanisms including localStorage manipulation, OAuth token theft, and Exchange folder permission modifications. Infrastructure dating to March 2026 suggests potential zero-day exploitation prior to Microsoft's May patch."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785495621",
        "to_ids": false,
        "type": "text",
        "uuid": "ad7d31b5-0c4b-48a7-b8ed-792065488ec2",
        "value": "Name: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit\nAuthor: AlienVault\nAdversary: TA488\nTags: [\"credential theft\", \"javascript implant\", \"ta488\", \"cve-2026-42897\", \"half-click exploit\", \"zimreaper\", \"outlook web access\", \"owareaper\", \"xss vulnerability\"]\nTgtd countries: []\nMlwr families: [\"OWAReaper\", \"ZimReaper\"]\nAttack_ids: [\"T1132.001\", \"T1056.001\", \"T1059.007\", \"T1071.004\", \"T1074.001\", \"T1114.001\", \"T1566.001\", \"T1140\", \"T1555.003\", \"T1528\", \"T1087.004\", \"T1041\", \"T1547.001\", \"T1098\", \"T1027\", \"T1203\", \"T1189\", \"T1071.001\", \"T1102.001\", \"T1048.003\"]\nIndustries: [\"Government\", \"Telecommunications\", \"Finance\", \"Hospitality\", \"Aerospace\", \"Defense\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785495621",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "322777f3-11d4-4c5c-a9b4-2b2fde835a94",
        "value": "TA488"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785495621",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "26fb2fee-c851-4058-bb7e-0657e22555fd",
        "value": "CVE-2026-42897"
      },
      {
        "category": "Network activity",
        "comment": "TA488 domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785648840",
        "to_ids": true,
        "type": "domain",
        "uuid": "12c82389-70f7-4e89-8e8d-51649ffb036e",
        "value": "acocdn.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "OWAReaper C&C",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785648861",
        "to_ids": true,
        "type": "domain",
        "uuid": "a71c12ba-c335-4f7b-a506-0b1691aa802e",
        "value": "dnsrecursive.eu",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "OWAReaper C&C",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785648882",
        "to_ids": true,
        "type": "domain",
        "uuid": "f300e1d0-473e-4c73-b68e-d04313037b04",
        "value": "tdndns.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "OWAReaper C&C",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785648903",
        "to_ids": true,
        "type": "domain",
        "uuid": "2beebc3a-33e2-41a3-8f61-f099e2a480f3",
        "value": "asecdns.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-07-29T10:46:31+00:00",
        "last_seen": "2026-07-30T11:10:54+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1785648924",
        "uuid": "f5b37546-29ac-4783-9c14-a954ee4312d7",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "md5",
            "timestamp": "1785648924",
            "to_ids": true,
            "type": "md5",
            "uuid": "6ab34243-07c1-4b25-9b91-3f70301495bd",
            "value": "791e450f020f6858d312df484f43f8d4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "sha1",
            "timestamp": "1785644317",
            "to_ids": true,
            "type": "sha1",
            "uuid": "5bd28215-5223-4c74-810a-199bb6cfe2d1",
            "value": "1c9f9dab1879fc5f0269d499ff8d7d405132cb36",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "sha256",
            "timestamp": "1785644317",
            "to_ids": true,
            "type": "sha256",
            "uuid": "a5476723-1888-4c0f-aa39-05cc773436e4",
            "value": "6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 02/08/2026\nLast-scan: 02/08/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "text",
            "timestamp": "1785644317",
            "to_ids": false,
            "type": "text",
            "uuid": "da1bb688-af50-489a-a051-94c33c287078",
            "value": "Type Description: HTML\nMicrosoft: Trojan:HTML/CVE-2026-42897.DA!MTB\nClamAV: None\nVT Total Detection: 21/75\nFirst Submission: 2026-07-29T10:46:31+00:00\nLast Submission: 2026-07-30T11:10:54+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1785644317",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "83208b19-5e15-40be-8b6b-6710b5d0563a",
            "value": "1536:WBbLAdxjmHKRqp6UF7n6fJXUXwpnlLHZW5:cbLAriHljYW8a"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1785644317",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "3cffe760-60c9-418a-8014-5e109d91b93a",
            "value": "68829"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "vhash",
            "timestamp": "1785644317",
            "to_ids": true,
            "type": "vhash",
            "uuid": "61ec92e5-3103-49fb-98bf-447e61001fd3",
            "value": "b65b6946b3136fb5ee0dab38bdec810f"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-07-29T10:46:31+00:00",
            "last_seen": "2026-07-30T11:10:54+00:00",
            "object_relation": "filename",
            "timestamp": "1785644317",
            "to_ids": true,
            "type": "filename",
            "uuid": "0fe98f4e-9da3-435e-a6d8-144db3336f07",
            "value": "6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4.html"
          }
        ]
      }
    ]
  }
}