• News/
  • https://www.theregister.com/2025/05/13/turkish_spies_messaging_app/

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

The Register
·
Jessica Lyons
·
Published May 13, 2025
·
Updated

Turkish spies exploited a zero-day bug in a messaging app to collect info on the Kurdish army in Iraq, according to Microsoft, which says the attacks began more than a year ago. Specifically, the snoops abused CVE-2025-27920, a directory traversal vulnerability in version 2.0.62 of messaging app Output Messenger, and the intrusions began in April 2024. The app's developer Srimax issued a software update in December to patch the hole, however not all users applied the fixes. The crew behind the intrusions, a Türkiye-affiliated espionage threat actor that Microsoft tracks as Marbled Dust, abused the flaw to steal user data belonging to the Kurdish military in Iraq, Redmond's threat intelligence team wrote on Monday. The Kurdish people live on land spanning Iran, Iraq, Syria, and Türkiye. The ethnic group aspires to create a sovereign state. Kurdish people have taken up arms to defend themselves against persecution. Türkiye opposes the formation of a Kurdish state, a motive for state-linked cyber crews to target Kurdish military operations. Srimax admitted to the flaw and published a security advisory in which it revealed "Attackers could access files such as configuration files, sensitive user data, or even source code, and depending on the file contents, this could lead to further exploitation, including remote code execution.” Srimax did not immediately respond to The Register's inquiries. Marbled Dust typically targets government institutions and organizations whose interest...

Read full article

Affected Software

2 affected components
Srimax Output Messenger=2.0.62
Srimax Output Messenger=2.0.62

Frequently Asked Questions

1

What is the main focus of the article?

The article discusses how a Türkiye-linked spy group exploited a zero-day vulnerability in the Srimax Output Messenger app to gather intelligence on the Kurdish army in Iraq.

2

What security threat does the article highlight?

The article highlights the use of a zero-day exploit in a messaging app that allowed Turkish spies to infiltrate and surveil military communications.

3

Which messaging app is reported to have a security vulnerability?

The affected messaging app is Srimax Output Messenger, specifically version 2.0.62.

4

How long have the spying attacks reportedly been occurring?

According to Microsoft, the spying attacks began over a year ago.

5

What implications does this incident have for messaging app security?

This incident underscores the critical need for robust security measures and timely updates in messaging applications to protect against zero-day vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203