← Threat Actors & APT Groups

TA488

Every article that identifies TA488 as responsible for or connected to reported activity.

MalwareInfosecurity Magazine·3 weeks ago

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

Russian-aligned threat actor TA488 has resumed operations with a sophisticated attack targeting Outlook Web Access (OWA) using a half-click exploit technique. The campaign deploys a custom implant called OWAReaper that demonstrates persistence capabilities even after system re-imaging, presenting a significant challenge for defenders attempting to remediate compromised environments.