RedmondOpening one email is enough to trigger compromise.
TA488, tied to the Kremlin, is exploiting a maximum-severity Exchange flaw patched in July; researchers say the backdoor survives password resets and full device re-imaging.
Removal requires action on the Exchange server itself — the gap between patch and application is the whole story.
Sources: Ars Technica