MoscowLaundry Bear is exploiting an Outlook webmail bug.
The Russia-linked group, exposed for a February webmail campaign, has moved to a fresh flaw in Microsoft’s Outlook Web Access, researchers said.
Its prior exposure did not end the campaign, and which targets it is now hitting is not known.
Sources: The Record