logo

Microsoft spots zero-day use in spy campaign against Kurdish military in Iraq

ID: 3f460a90-6be4-5529-81cd-effc08b19f0f

STIX ID: report--3f460a90-6be4-5529-81cd-effc08b19f0f

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-05-12

Date Updated: 2026-05-01

...
...

Researchers report that the Turkish-aligned APT 'Marbled Dust' exploited a zero-day (CVE-2025-27920) in Output Messenger to upload malicious files to server startup directories and spy on Kurdish military operations in Iraq; Microsoft links the activity to groups tracked as Sea Turtle/UNC1326, notes possible credential-interception techniques (DNS hijacking/typosquatting), and says Srimax has issued patches including for a second non-exploited CVE (CVE-2025-27921).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.