216.73.216.6

Marbled Dust leverages zero-day in Output Messenger for regional espionage

· Published 13/05/2025 02:58 · Modified 13/05/2025 08:30

Export JSON

Essential information

Published
13/05/2025 02:58
Modified
13/05/2025 08:30
Tags
2025-05-12 2025-05-13 CVE-2025-27920 CVE-2025-27921 backdoor data exfiltration directory traversal dns hijacking espionage golang iraq kurdistan om.vbs omclientservice.exe omserverservice.exe omserverservice.vbs output messenger zero-day
Related entities
2 vulnerabilities (cve), 3 observables, 1 intrusion sets (apt), 10 techniques (mitre), 4 malware, 3 others

Description

A Türkiye-affiliated threat actor, Marbled Dust, has been exploiting a vulnerability in since April 2024. The attacks target Kurdish military entities in , allowing the actor to deliver malicious files and exfiltrate data. The exploit involves a vulnerability in the Server Manager application, enabling authenticated users to upload malicious files to the server's startup directory. Marbled Dust's attack chain includes dropping malicious VBS and EXE files, using backdoors for , and leveraging the system architecture to access user communications and sensitive data.

External references