Looks like Void Blizzard — alleged to be the Russian cyber firm Yutek-NN — may also have been deploying an Outlook no-click (or half-click) zero day. Neat research here from @greg-l.bsky.social & the @proofpoint.com team:
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...