A Türkiye-backed cyberespionage group exploited a zero-day vulnerability to attack Output Messenger users linked to the Kurdish military in Iraq. Microsoft Threat Intelligence analysts who spotted these attacks also discovered the security flaw (CVE-2025-27920) in the LAN messaging application, a directory traversal vulnerability that can let authenticated attackers access sensitive files outside the intended directory or deploy malicious payloads on the server's startup folder. "Attackers could access files such as configuration files, sensitive user data, or even source code, and depending on the file contents, this could lead to further exploitation, including remote code execution," Srimax, the app's developer, explains in a security advisory issued in December when the bug was patched with the release of Output Messenger V2.0.63. Microsoft revealed on Monday that the hacking group (also tracked as Sea Turtle, SILICON, and UNC1326) targeted users who hadn't updated their systems to infect them with malware after gaining access to the Output Messenger Server Manager application. After compromising the server, Marbled Dust hackers could steal sensitive data, access all user communications, impersonate users, gain access to internal systems, and cause operational disruptions. "While we currently do not have visibility into how Marbled Dust gained authentication in each instance, we assess that the threat actor leverages DNS hijacking or typo-squatted domains to intercept, l...
Output Messenger flaw exploited as zero-day in espionage attacks
BleepingComputer
·Sergiu Gatlan
·Published May 12, 2025
·Updated
Affected Software
3 affected components
Srimax Output Messenger=V2.0.62
Srimax Output Messenger=V2.0.63
Srimax Output Messenger=2.0.63
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Output Messenger that has been exploited by a Türkiye-backed cyberespionage group.
2
What security implications are discussed in the article?
The article highlights potential risks for Output Messenger users, particularly those linked to the Kurdish military in Iraq.
3
What products or software are affected by this zero-day vulnerability?
The affected software is Srimax Output Messenger, specifically versions V2.0.62 and V2.0.63.
4
What type of attacks are mentioned in relation to the vulnerability?
The article mentions espionage attacks targeting users of Output Messenger.
5
Who discovered the exploitation of the vulnerability?
Microsoft Threat Intelligence analysts discovered the exploitation of the Output Messenger vulnerability.