TA488 has been associated with a new campaign that transforms routine Outlook Web Access email into a gateway for mailbox compromise This article explores attacker manipulate mailbox. . A poorly sanitized HTML script in JavaScript (Source – Proofpoint) allows an attacker to manipulate mailbox folder permissions, granting low-privileged access to default account owners without needing password resets or a full computer rebuild.
The OWAReaper infection chain involves command handling via crafted GitHub commit messages and incoming emails, as well as HTTPS traffic through image delivery services with DNS tunneling for additional security bypasses. Security teams should revoke and audit Exchange Web Services tokens for affected add-ins, remove improper Default-user folder permissions, clear affected Outlook browser storage, and monitor or block connections to known command-and-control infrastructure.
Security teams should investigate unexpected Outlook Web Access behavior, including suspicious scripts, unusual permission changes, and anomalous webmail sessions while continuing to educate users about deceptive yet seemingly harmless messages. Indicators of compromise (IoCs): - Domain: asecdns.com OWAReaper command-and-control infrastructure - Domain: acocdn.com OWAReaper command-and-control infrastructure and HTTPS data relay - Domain: dnsrecursive.eu OWAReaper command-and-control infrastructure - Domain: tdndns.com OWAReaper command-and-control infrastructure Type Indicator Description HTML message body containing the exploit and OWAReaper payload Securely integrate into authorized cybersecurity platforms like MISP, VirusTotal, or through your Security Information and Event Management (SIEM). Utilize ANY.RUN to bolster your Security Operations Center capabilities.












