Marbled Dust leverages zero-day in Output Messenger for regional espionage
ID: 5d0a9dca-4662-57e9-b9d4-419844325ee5
STIX ID: report--5d0a9dca-4662-57e9-b9d4-419844325ee5
Feed Name: Microsoft Security
Microsoft Threat Intelligence reports that the Türkiye‑affiliated espionage actor Marbled Dust has actively exploited a zero‑day directory traversal vulnerability (CVE-2025-27920) in Output Messenger to install GoLang backdoors (OMServerService.exe / OMClientService.exe), collect credentials, and exfiltrate data from targets associated with the Kurdish military in Iraq; the blog provides technical analysis, IOCs (e.g., api.wordinfos.com), hunting queries, and recommended mitigations including applying the Output Messenger patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
