Microsoft spots zero-day use in spy campaign against Kurdish military in Iraq
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-27920 +1 in the same advisory: …27921 | Directory Traversal in Srimax Output Messenger Before 2.0.63 Output Messenger versions before 2.0.63 contain a directory traversal flaw (CWE-24) caused by improper handling of file paths in application parameters. An attacker who submits ../ sequences in these parameters can reach files outside the intended directory, potentially retrieving configuration files or other sensitive files from the server. The CVSS vector indicates network access with low privileges is required, so a low-privileged user account is sufficient to trigger the flaw. Any organization running Output Messenger below 2.0.63 is affected, and the flaw has been actively exploited: a Türkiye-aligned APT group reportedly used it as a zero-day against Kurdish military servers in Iraq, deploying Golang backdoors, an activity also observed by Microsoft. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-05-19, requiring federal agencies to apply vendor mitigations, follow BOD 22-01 guidance, or discontinue use of the product. Do: Upgrade Srimax Output Messenger to version 2.0.63 or later per the vendor's instructions, as required by CISA's KEV entry (or follow BOD 22-01 guidance for federal cloud services). Organizations that cannot patch promptly should restrict network access to Output Messenger Server and review affected hosts for signs of compromise, including unexpected Golang backdoor binaries or processes and unauthorized access to or modification of configuration files. | 8.8 group max | 2% | KEV |
| nicheunknown; likely no more than thousands of on-premises deployments (niche enterprise chat product) |
Full article406 words · extracted from therecord.media · click to collapse
A cyber-espionage group aligned with the Turkish government appears to have exploited a zero-day vulnerability in a messaging app to spy on Kurdish military operations in Iraq, researchers said Monday. The hackers, tracked as Marbled Dust, have been breaking into accounts of Output Messenger — an app commonly used for workplace and organizational chats — since April 2024, according to Microsoft Threat Intelligence. The team said it “assesses with high confidence that the targets of the attack are associated with the Kurdish military operating in Iraq, consistent with previously observed Marbled Dust targeting priorities.” The Kurdish militant group PKK said Monday that it was disbanding and disarming after decades of conflict with Turkey. Most of Iraq’s Kurds live in a semi-autonomous region that has a border with Turkey. Marbled Dust’s activities overlap with operations that other companies track as Sea Turtle or UNC1326. The hackers are known for targeting entities in Europe and the Middle East, “particularly government institutions and organizations that likely represent counter interests to the Turkish government, as well as targets in the telecommunications and information technology sectors,” Microsoft said. The previously undocumented Output Messenger bug, CVE-2025-27920, could allow an authenticated user to upload malicious files into the server’s startup directory. Microsoft said it’s not sure how Marbled Dust got access to authenticated user accounts in every instance, but it’s possible that the group uses techniques like DNS hijacking or typosquatted domains to intercept web traffic and capture individuals’ credentials. Output Messenger’s developer, India-based Srimax, issued an update for the software after Microsoft notified it of the vulnerability. The researchers said they also discovered a second bug, CVE-2025-27921, that does not appear to have been exploited. The Srimax patches cover that flaw, too. Exploiting the first vulnerability could allow attackers to “gain indiscriminate access to the communications of every user, steal sensitive data and impersonate users, which could lead to operational disruptions, unauthorized access to internal systems, and widespread credential compromise,” Microsoft said.
No previous article
No new articles
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-zero-day-spy-campaign