Turkish spies exploited a zero-day bug in a messaging app to collect info on the Kurdish army in Iraq, according to Microsoft, which says the attacks began more than a year ago. Specifically, the snoops abused CVE-2025-27920, a directory traversal vulnerability in version 2.0.62 of messaging app Output Messenger, and the intrusions began in April 2024. The app's developer Srimax issued a software update in December to patch the hole, however not all users applied the fixes. The crew behind the intrusions, a Türkiye-affiliated espionage threat actor that Microsoft tracks as Marbled Dust, abused the flaw to steal user data belonging to the Kurdish military in Iraq, Redmond's threat intelligence team wrote on Monday. The Kurdish people live on land spanning Iran, Iraq, Syria, and Türkiye. The ethnic group aspires to create a sovereign state. Kurdish people have taken up arms to defend themselves against persecution. Türkiye opposes the formation of a Kurdish state, a motive for state-linked cyber crews to target Kurdish military operations. Srimax admitted to the flaw and published a security advisory in which it revealed "Attackers could access files such as configuration files, sensitive user data, or even source code, and depending on the file contents, this could lead to further exploitation, including remote code execution.” Srimax did not immediately respond to The Register's inquiries. Marbled Dust typically targets government institutions and organizations whose interest...
Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq
The Register
·Jessica Lyons
·Published May 13, 2025
·Updated
Affected Software
2 affected components
Srimax Output Messenger=2.0.62
Srimax Output Messenger=2.0.62
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses how a Türkiye-linked spy group exploited a zero-day vulnerability in the Srimax Output Messenger app to gather intelligence on the Kurdish army in Iraq.
2
What security threat does the article highlight?
The article highlights the use of a zero-day exploit in a messaging app that allowed Turkish spies to infiltrate and surveil military communications.
3
Which messaging app is reported to have a security vulnerability?
The affected messaging app is Srimax Output Messenger, specifically version 2.0.62.
4
How long have the spying attacks reportedly been occurring?
According to Microsoft, the spying attacks began over a year ago.
5
What implications does this incident have for messaging app security?
This incident underscores the critical need for robust security measures and timely updates in messaging applications to protect against zero-day vulnerabilities.