Marbled Dust leverages zero-day in Output Messenger for regional espionage
Essential information
- Published
- 13/05/2025 02:58
- Modified
- 13/05/2025 08:30
- Tags
- 2025-05-12 2025-05-13 CVE-2025-27920 CVE-2025-27921 backdoor data exfiltration directory traversal dns hijacking espionage golang iraq kurdistan om.vbs omclientservice.exe omserverservice.exe omserverservice.vbs output messenger zero-day
- Related entities
- 2 vulnerabilities (cve), 3 observables, 1 intrusion sets (apt), 10 techniques (mitre), 4 malware, 3 others
Description
A Türkiye-affiliated espionage threat actor, Marbled Dust, has been exploiting a zero-day vulnerability in Output Messenger since April 2024. The attacks target Kurdish military entities in Iraq, allowing the actor to deliver malicious files and exfiltrate data. The exploit involves a directory traversal vulnerability in the Output Messenger Server Manager application, enabling authenticated users to upload malicious files to the server's startup directory. Marbled Dust's attack chain includes dropping malicious VBS and EXE files, using GoLang backdoors for data exfiltration, and leveraging the Output Messenger system architecture to access user communications and sensitive data.