The Good, the Bad and the Ugly in Cybersecurity – Week 20
Essential information
- Published
- 16/05/2025 16:33
- Modified
- 21/05/2025 20:49
- Tags
- 2025-05-16 CVE-2025-27920 botnet dark web dns hijacking doppelpaymer kurdish military npm omclientservice.exe omserverservice.exe output messenger ransomware zero-day
- Related entities
- 1 vulnerabilities (cve), 1 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware, 7 others
Description
This intelligence update covers recent cybersecurity events. In positive developments, global authorities disrupted a major botnet, arrested a ransomware actor, and dismantled a dark web marketplace. On the negative side, a malicious NPM package was discovered hiding multi-stage malware using Unicode and Google Calendar. The most concerning development involves cyberspies exploiting a zero-day vulnerability in Output Messenger to target Kurdish military users in Iraq, showcasing increased capabilities of the Marbled Dust threat group.