DISCARDED: Tales From the Threat Research Trenches
DISCARDED: Tales From the Threat Research Trenches · Aug 11, 2026 · 1:03:14
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
Hello to all our cyber stars!
Host Selena Larson is joined by co-host Sarah Sabotka, along with returning guest Greg Lesnewich, Principal Threat Research Engineer, and Staff Threat Researcher Mark Kelly, for a follow-up to last episode's half-click deep dive — this time tracking how the technique is spreading beyond TA458 and TA488 into a brand-new Chinese cluster.
Greg picks up where last week left off with TA488 (aka Void Blizzard, aka Laundry Bear): after going quiet in February following exposure, the group resurfaced on July 22 — one day before Proofpoint's joint advisory with the NSA — with a new half-click exploit against Microsoft Outlook Web Access. The payload, a previously unseen browser-resident implant called OWAReaper, is built for persistence: it survives credential rotation, browser restarts, and even a full device reimage, and it phones home via GitHub commit messages and image requests proxied through legitimate CDNs like Slack and WordPress.
Mark then brings a new actor into the half-click conversation: UNK_MassTraction, a suspected China-aligned cluster exploiting a cross-site scripting flaw in Roundcube to target physics and engineering departments at North American universities — chosen, it turns out, specifically because they were running vulnerable Roundcube instances. The infection chain drops either a webshell or VShell, a Linux backdoor of murky, possibly commercially-developed origin that keeps popping up across Chinese state-sponsored intrusions.
The conversation covers:
Plus: Gus the dog's podcast debut, security awareness training in a world where opening an email can be enough, and shoutouts to Tom Lancaster (Volexity) and Microsoft's patch team.
Resources Mentioned:
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
TA488 Targets Zimbra Mailservers with Half-Click Exploits
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Stay ahead of emerging threats, and subscribe! Happy hunting!
Episodes: DISCARDED: Tales From the Threat Research Trenches