Opening one email is enough to trigger compromise.

TA488, tied to the Kremlin, is exploiting a maximum-severity Exchange flaw patched in July; researchers say the backdoor survives password resets and full device re-imaging.

Removal requires action on the Exchange server itself — the gap between patch and application is the whole story.

Sources: Ars Technica