Russian threat actors previously tied to Zimbra exploitation have pivoted to targeting Microsoft Outlook Web Access (OWA) in a sophisticated persistence campaign. The group exploits an unpatched OWA vulnerability to maintain mailbox access even after organisations rotate compromised credentials, creating a severe operational security risk.

The attacks began on July 22, 2026, and target U.S. and European government entities alongside organisations in telecommunications, financial services, hospitality, and aerospace sectors. This victim profile indicates espionage objectives rather than opportunistic financial theft.

The threat actors' ability to retain access post-credential rotation suggests the OWA vulnerability allows privilege escalation or session hijacking independent of standard authentication mechanisms. This breaks a fundamental security assumption many organisations rely on: rotating compromised passwords will terminate attacker access. Instead, defenders face an adversary that can bypass this containment measure entirely.

The connection to previous Zimbra exploitation demonstrates this group possesses deep knowledge of collaboration platform vulnerabilities. They appear to be actively researching and weaponising flaws across multiple email and messaging systems, suggesting a coordinated intelligence-gathering operation rather than commodity malware distribution.

Organisations using OWA should prioritise several immediate actions. First, assume credential compromise is possible and implement enhanced monitoring for anomalous mailbox access patterns, particularly from unusual geographic locations or times. Second, review OWA server logs from July 22 onwards for suspicious authentication sequences. Third, check for forwarding rules or delegate access added to compromised mailboxes that could persist after credential rotation.

Patching status remains unclear from available information. If Microsoft has not released a patch, administrators should implement network segmentation to restrict OWA access to known corporate IP ranges and require multi-factor authentication even for internal connections. Organisations in critical infrastructure sectors should treat this as a priority incident response matter.

The targeting of government and strategic industry sectors