The Server Was Fixed. Persistent Access Wasn’t.
Persistent access is one of the few compromise patterns that can survive a fully executed recovery. In August, researchers disclosed that attackers exploiting Microsoft Exchange Server had deployed a browser-based implant — internally documented as OWAReaper — that modified mailbox permissions in a way that outlasted both credential rotation and complete server rebuilds. The recovery…
