logo

Marbled Dust leverages zero-day in Output Messenger for regional espionage

ID: 5d0a9dca-4662-57e9-b9d4-419844325ee5

STIX ID: report--5d0a9dca-4662-57e9-b9d4-419844325ee5

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-05-12

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence reports that the Türkiye‑affiliated espionage actor Marbled Dust has actively exploited a zero‑day directory traversal vulnerability (CVE-2025-27920) in Output Messenger to install GoLang backdoors (OMServerService.exe / OMClientService.exe), collect credentials, and exfiltrate data from targets associated with the Kurdish military in Iraq; the blog provides technical analysis, IOCs (e.g., api.wordinfos.com), hunting queries, and recommended mitigations including applying the Output Messenger patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.