Cyware Daily Threat Intelligence - July 30, 2026

Attackers are quietly hijacking Outlook Web Access mailboxes and siphoning sensitive correspondence by exploiting a cross-site scripting flaw, with OWAReaper enabling durable account takeovers across European government, telecom, and financial sectors. Cyware.com highlights how a single crafted email can trigger credential theft and persistent mailbox access, with Microsoft issuing a security update after Proofpoint tracked active exploitation.
A surge in Android device takeovers is unfolding in Italy, where the Copybara malware family abuses Accessibility services to keylog, stream screens, and remotely control victims’ phones. Attackers use vishing and phishing to target N26 users, leveraging MQTT command channels and VPN evasion to turn smartphones into interactive fraud tools.
Critical vulnerabilities in Cisco’s Secure Firewall Management Center and VMware’s vCenter and ESX platforms are under active attack or urgent patching, with CVE-2026-20316 already exploited in the wild. CISA’s directives require immediate remediation and compromise checks, while VMware’s trio of high-severity bugs threaten core data center operations if left unpatched.
Threat groups including TA488 and Lazarus Group are escalating mailbox takeovers and watering-hole attacks, with campaigns compromising 72 organizations and abusing 15 legitimate websites. ShinyHunters is pivoting to vishing and SaaS account takeovers, exposing healthcare data across multiple cloud platforms.
Top Malware Reported in the Last 24 Hours
OWAReaper steals mail from Outlook Web Access
OWAReaper is a webmail backdoor that exploits a cross-site scripting flaw (CVE-2026-42897) in Outlook Web Access to steal emails and credentials from within the reading pane. OWAReaper can disable pop-ups, block right-click actions, and use hidden iframes in the IndexedDB message cache to evade detection. OWAReaper plants invisible input fields to capture logins, providing attackers with persistent access to compromised mailboxes. Infection occurs when a victim opens a specially crafted email in OWA, triggering malicious JavaScript. OWAReaper targets European government agencies, telecom, financial, hospitality, and aviation organizations. Proofpoint reported active exploitation beginning in March, with Microsoft releasing a security update on June 9.
Copybara hijacks Android via Accessibility abuse
Copybara is an Android malware family that abuses Accessibility services to take over devices. Copybara enables keylogging, screen streaming, and remote control of victim devices. Copybara uses a multi-stage dropper and a local VPN to bypass Play Protect checks, making installation and operation easier for attackers. Infection is delivered through vishing and phishing campaigns, including rogue support emails targeting N26 users. Copybara relies on MQTT command channels for remote instructions and high-volume data transfer. Recommended actions include monitoring for MQTT-driven behavior and blocking identified IOCs.
AtlasRAT hides in fake Flash installer
AtlasRAT is a modular Windows remote-access trojan built around a four-stage, in-memory loader chain. AtlasRAT enables keylogging, targeted process injection, and plugin execution while remaining off disk. AtlasRAT starts as a Delphi executable disguised as an AGE Flash Player installer, reconstructing encrypted fragments using Base64, XOR, and AES-256-CBC before delivering its payload. AtlasRAT injects code into WeChat.exe and can download and run additional files, providing operators with surveillance and control. Researchers identified 146 unique samples, suggesting use by multiple operators. Recommended actions include blocking specific filenames and monitoring network indicators linked to command-and-control activity.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-20316 and CVE-2026-20079: Cisco FMC zero-day exposes firewall managers
CVE-2026-20316 is a hard-coded credential vulnerability in Cisco Secure Firewall Management Center (FMC) software, while CVE-2026-20079 is a critical authentication bypass (CVSS 10.0) in the same product. Successful exploitation of CVE-2026-20316 allows attackers to gain unauthorized access and reach sensitive data via the web interface, while CVE-2026-20079 could let attackers run scripts and commands as root. CVE-2026-20316 is actively exploited in zero-day attacks; no exploitation is reported for CVE-2026-20079. Cisco and CISA have issued guidance, with CISA adding CVE-2026-20316 to the Known Exploited Vulnerabilities Catalog and requiring federal agencies to verify system compromise before patching. Affected systems should apply Cisco hot fixes and monitor for artifacts such as license.tmp in /var/tmp.
CVE-2026-42897: Russian-aligned TA488 takes over Exchange mailboxes
CVE-2026-42897 is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) affecting Exchange Server 2016, 2019, and Subscription Edition, with no CVSS score stated. Successful exploitation lets attackers hijack mailboxes and set server-side permissions that persist through password resets and device rebuilds. CVE-2026-42897 is actively exploited in the wild, with the campaign starting on July 22 after infrastructure was set up in March. CSO Online reports TA488 targeted government, telecommunications, financial, hospitality, and aerospace sectors, using the OWAReaper implant that removes exploit code after execution. Microsoft’s July 2026 Exchange security update addresses the issue.
VMware patches critical vCenter and ESX bugs
CVE-2026-59309 (authentication bypass, CVSS 9.8) and CVE-2026-59310 (path traversal, CVSS 9.8) affect VMware vCenter, while CVE-2026-41703 (out-of-bounds write, CVSS 9.3) impacts ESX hosts. Successful exploitation could allow attackers to gain unauthorized access to management systems or execute code on virtualization hosts, disrupting business-critical applications. No active exploitation is reported, but VMware products are frequently targeted, with CISA tracking 26 unique VMware vulnerabilities, including 11 in vCenter. Patches are available, and organizations are advised to implement network segmentation and access controls.
Top Threat Actors Reported in Last 24 hours
TA488 turns Exchange OWA into takeovers
TA488 is a Russia-aligned threat group suspected of espionage and persistent access operations. TA488 exploits a cross-site scripting flaw (CVE-2026-42897) in Microsoft Exchange OWA to hijack mailboxes using a “half-click” technique. TA488 deploys the OWAReaper implant to set server-side mailbox permissions that persist through password resets and device rebuilds. TA488 targets government teams and regulated industries, exposing sensitive communications over extended periods. The campaign began on July 22, with infrastructure established in March, indicating possible zero-day exploitation. Proofpoint and CSO Online reported the activity.
Lazarus-linked watering holes hit South Korea
Lazarus Group (also tracked as Hidden Cobra) is a state-sponsored threat actor suspected of North Korean origin, focused on espionage and financial gain. Lazarus Group exploited a zero-day in AnySign4PC (versions 1.1.4.4 to 1.1.4.6) to deliver SIGNBT or COPPERHEDGE backdoors via South Korean watering-hole sites. Lazarus Group used PNG images for key exchange and executed payloads inside legitimate processes, expanding access through privilege escalation and lateral movement. Lazarus Group targeted news, healthcare, and education sectors, compromising staff who visited trusted sites. The campaign compromised 72 organizations and abused 15 legitimate websites, with tooling including Mimikatz and NLBrute.
ShinyHunters vishes healthcare into SaaS theft
ShinyHunters is a data-theft and extortion group suspected of criminal origin, with a primary motive of large-scale data exfiltration. ShinyHunters uses custom phishing kits for vishing to manipulate employees into resetting passwords or changing authentication methods. ShinyHunters pivots into connected cloud services such as Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, and Google Drive to steal data rapidly. ShinyHunters targets healthcare organizations, exposing patient and business records across multiple SaaS platforms. Recent incidents affected iRhythm and OneMedical, as reported by Health-ISAC.
Frequently Asked Questions
What is OWAReaper? OWAReaper is a webmail backdoor tied to an Outlook Web Access (OWA) cross-site scripting flaw, CVE-2026-42897, letting attackers steal emails and credentials from inside the reading pane. Once a victim opens a specially crafted email in OWA, it runs malicious JavaScript that can disable pop-ups and even block right-click actions to reduce the user’s ability to spot or interrupt what’s happening.
What is Copybara? Copybara is an Android malware family that takes over devices by abusing Accessibility services, giving operators the ability to keylog, stream screens, and remotely control what victims see and tap. In a recent Italy-focused fraud scheme targeting N26 users, attackers used vishing and phishing—along with a rogue “support” email—to trick victims into installing a malicious Android package.
What is AtlasRAT? AtlasRAT is a modular Windows remote-access trojan built around a four-stage, in-memory loader chain, designed to stay off disk while enabling capabilities like keylogging and targeted process injection. It typically starts as a Delphi executable disguised as an AGE Flash Player installer, then rebuilds encrypted fragments using Base64, XOR, and AES-256-CBC before delivering the final payload.
What is CVE-2026-20316? Cisco says attackers are exploiting a hard-coded credential flaw in Secure Firewall Management Center (FMC) software (CVE-2026-20316) to gain unauthorized access and reach sensitive data through the product’s web interface. In parallel, Cisco also patched a separate critical authentication bypass in FMC (CVE-2026-20079, CVSS 10.0) that could let an attacker run scripts and commands as root if abused.
What is TA488? A Russia-aligned threat group tracked as TA488 is exploiting a Microsoft Exchange Outlook Web Access (OWA) flaw to hijack mailboxes with a “half-click” technique, letting attackers set server-side permissions that can survive password resets and even device rebuilds. The issue is tracked as CVE-2026-42897, described as a cross-site scripting (XSS) vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition, and the attack triggers when a target views a crafted email in OWA.
What is CVE-2026-59309? VMware has shipped patches for a trio of high-severity flaws that could let attackers break into vCenter or run code on ESX hosts—systems that often sit at the center of enterprise data centers. The company lists CVE-2026-59309 (authentication bypass) and CVE-2026-59310 (path traversal) at CVSS 9.8, both impacting vCenter, plus CVE-2026-41703 (out-of-bounds write in the VMXNET3 adapter) at CVSS 9.3 impacting ESX.
What is Lazarus Group? A state-sponsored campaign suspected of ties to Lazarus Group has been caught turning trusted South Korean websites into infection points for visitors, blending spear-phishing with watering-hole attacks. They exploited a zero-day in AnySign4PC affecting versions 1.1.4.4 to 1.1.4.6 (fixed in 1.1.5.0) to deliver the SIGNBT or COPPERHEDGE backdoors.
What is ShinyHunters? ShinyHunters, a data-theft and extortion crew, is increasingly breaking into healthcare by talking their way past identity controls instead of relying on malware. Health-ISAC said they use custom phishing kits for vishing to manipulate employees into resetting passwords or changing authentication methods, enabling single sign-on (SSO) account takeovers.