ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-27920CVE-2025-27921

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-27920
+1 in the same advisory: …27921
Directory Traversal in Srimax Output Messenger Before 2.0.63

Output Messenger versions before 2.0.63 contain a directory traversal flaw (CWE-24) caused by improper handling of file paths in application parameters. An attacker who submits ../ sequences in these parameters can reach files outside the intended directory, potentially retrieving configuration files or other sensitive files from the server. The CVSS vector indicates network access with low privileges is required, so a low-privileged user account is sufficient to trigger the flaw. Any organization running Output Messenger below 2.0.63 is affected, and the flaw has been actively exploited: a Türkiye-aligned APT group reportedly used it as a zero-day against Kurdish military servers in Iraq, deploying Golang backdoors, an activity also observed by Microsoft. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-05-19, requiring federal agencies to apply vendor mitigations, follow BOD 22-01 guidance, or discontinue use of the product.

Do: Upgrade Srimax Output Messenger to version 2.0.63 or later per the vendor's instructions, as required by CISA's KEV entry (or follow BOD 22-01 guidance for federal cloud services). Organizations that cannot patch promptly should restrict network access to Output Messenger Server and review affected hosts for signs of compromise, including unexpected Golang backdoor binaries or processes and unauthorized access to or modification of configuration files.

8.8
group max
2% KEV
  • Srimax Output Messenger all versions before 2.0.63
nicheunknown; likely no more than thousands of on-premises deployments (niche enterprise chat product)

Indicators of compromiseAll →

TypeIndicatorContext
domainwordinfos.coms a Golang backdoor that contacts a hard-coded domain ("api.wordinfos[.]com") for data exfiltration. "On the client side, the install
Full article611 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 13, 2025Zero-Day / Vulnerability

A Türkiye-affiliated threat actor exploited a zero-day security flaw in an Indian enterprise communication platform called Output Messenger as part of a cyber espionage attack campaign since April 2024.

"These exploits have resulted in a collection of related user data from targets in Iraq," the Microsoft Threat Intelligence team said. "The targets of the attack are associated with the Kurdish military operating in Iraq, consistent with previously observed Marbled Dust targeting priorities."

The activity has been attributed to a threat group it tracks as Marbled Dust (formerly Silicon), which is also known as Cosmic Wolf, Sea Turtle, Teal Kurma, and UNC1326. The hacking crew is believed to have been active since at least 2017, although it wasn't until two years later that Cisco Talos documented attacks targeting public and private entities in the Middle East and North Africa.

Early last year, it was also identified as targeting telecommunication, media, internet service providers (ISPs), information technology (IT)-service providers, and Kurdish websites in the Netherlands.

Microsoft has assessed with moderate confidence that the threat actor has conducted some sort of reconnaissance beforehand to determine if its targets are Output Messenger users and then leverage the zero-day to distribute malicious payloads and exfiltrate data from targets.

The vulnerability in question is CVE-2025-27920, a directory traversal vulnerability affecting version 2.0.62 that allows remote attackers to access or execute arbitrary files. The issue has been addressed by its developer Srimax as of late December 2024 with version 2.0.63. The company, however, makes no mention of the flaw being exploited in the wild in its advisory.

The attack chain starts with the threat actor gaining access to the Output Messenger Server Manager application as an authenticated user. It's believed that Marbled Dust uses techniques like DNS hijacking or typosquatted domains to intercept the credentials required for authentication.

The access is then abused to collect the user's Output Messenger credentials and exploit CVE-2025-27920 to drop payloads like "OM.vbs" and "OMServerService.vbs" to the server startup folder and "OMServerService.exe" to the server's "Users/public/videos" directory.

In the next phase, the threat actor uses "OMServerService.vbs" to invoke "OM.vbs" and "OMServerService.exe," the latter of which is a Golang backdoor that contacts a hard-coded domain ("api.wordinfos[.]com") for data exfiltration.

"On the client side, the installer extracts and executes both the legitimate file OutputMessenger.exe and OMClientService.exe, another Golang backdoor that connects to a Marbled Dust command-and-control (C2) domain," Microsoft noted.

"This backdoor first performs a connectivity check via a GET request to the C2 domain api.wordinfos[.]com. If successful, a second GET request is sent to the same C2 containing hostname information to uniquely identify the victim. The response from the C2 is then directly executed using the command 'cmd /c' which instructs the Windows command prompt to run a specific command and then terminate."

At one case involved a victim device with Output Messenger client software installed connecting to an IP address previously identified as used by Marbled Dust for likely data exfiltration.

The tech giant also noted that it discovered a second flaw, reflected cross-site scripting (XSS) vulnerability in the same version (CVE-2025-27921), although it said it found no evidence of it being weaponized in real-world attacks.

"This new attack signals a notable shift in Marbled Dust’s capability while maintaining consistency in their overall approach," Microsoft said. "The successful use of a zero-day exploit suggests an increase in technical sophistication and could also suggest that Marbled Dust’s targeting priorities have escalated or that their operational goals have become more urgent."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/05/turkiye-hackers-exploited-output.html