Zero-Day in Output Messenger Exploited for Malware Deployment

Zero-Day in Output Messenger Exploited for Malware Deployment

Espionage Group Leverages Undisclosed Flaw in Output Messenger to Target Kurdish Military Networks

A previously unknown security flaw in Output Messenger has been weaponized in a targeted cyber-espionage campaign aimed at Kurdish defense infrastructure in Iraq, according to a new investigation by Microsoft Threat Intelligence. The attackers, identified as the advanced persistent threat (APT) group Marbled Dust, have been actively exploiting this zero-day vulnerability since at least April 2024 to infiltrate systems, exfiltrate data, and execute malicious code within victim environments.

Exploitation of Trusted Enterprise Communication Tools

Output Messenger—widely adopted for secure, internal messaging across enterprise networks—harbors a severe directory traversal flaw now tracked as CVE-2025-27920. This vulnerability allows authenticated users to upload arbitrary files to the system’s startup path, granting persistent code execution on compromised servers.

Microsoft researchers uncovered that Marbled Dust targets systems that utilize Output Messenger, tailoring attacks to users linked to Kurdish military units. This behavior is consistent with the group’s established operational focus, which has historically aligned with Turkish geopolitical interests.

Rapid Vendor Response to Coordinated Disclosure

Upon identifying the exploitation, Microsoft promptly informed Srimax, the developer behind Output Messenger. In response, the company issued patches to close the security gap, limiting further exposure to this exploit.

Campaign Indicators and Attack Tactics

Marbled Dust is believed to conduct reconnaissance to determine whether potential victims utilize Output Messenger, likely as a prelude to credential theft. Although the mechanism for initial access remains uncertain, Microsoft suspects techniques such as DNS hijacking or the use of typosquatted domains to harvest valid login credentials.

Once authenticated access is gained, attackers deploy the exploit to deliver several malicious files:

  • OMServerService.vbs and OM.vbs to the startup directory for persistence
  • OMServerService.exe to Users/public/videos, disguised among common files

Strategic and Technical Escalation

Microsoft’s threat analysts interpret the use of an undisclosed vulnerability as a sign of increasing technical maturity within Marbled Dust’s operations. The escalation in both method and target scope suggests a shift in strategic urgency or evolving geopolitical objectives.

Coordinated Backdoor Deployment Reveals Deep Intrusion Capabilities in Output Messenger Attacks

A deeper analysis of the ongoing cyber campaign targeting Output Messenger users has revealed a coordinated effort to deploy multiple backdoors, enabling sustained access to compromised systems and broad-scale data theft. The attackers behind the campaign—tracked as Marbled Dust—have crafted a dual-access strategy that affects both server and client components of the chat platform.

Two-Pronged Backdoor Strategy

On the server side, a custom backdoor written in GoLang is triggered post-compromise, establishing persistent communication with a command-and-control (C2) server hosted at api.wordinfos[.]com. This backdoor allows remote operators to issue commands, extract data, and adjust payloads in real time.

Simultaneously, compromised client machines receive a second payload: OMClientService.exe. Masquerading as a legitimate component of the Output Messenger suite, this malware runs quietly in the background, harvesting system metadata and relaying it to the same C2 infrastructure used by the server-based backdoor. It also listens for commands that enable attackers to further probe or control the infected device.

Tool-Based Data Extraction

In one documented incident, Marbled Dust operatives utilized PuTTY’s Plink utility, a command-line SSH tunneling tool, to exfiltrate archived data. The stolen files—compressed into RAR archives—were stealthily transferred through this encrypted channel, avoiding traditional detection mechanisms.

System-Level Access Equals Total Surveillance

By compromising the Output Messenger server, attackers effectively insert themselves into the heart of internal communications. “Control of the server means control of the network,” a Microsoft threat analyst noted. “They’re able to read messages, extract private data, and even pose as legitimate users—all without triggering alarms.”

Marbled Dust: A Familiar Threat with New Tools

Marbled Dust is assessed by Microsoft as a state-aligned threat group with operational ties to Türkiye. Their tactics align closely with activity attributed by other cybersecurity firms to Sea Turtle and UNC1326. The group maintains a focus on high-value targets across Europe and the Middle East—particularly within government, telecom, and technology sectors.

Mitigation Guidance

Microsoft urges all organizations using Output Messenger to apply the following updates and precautions:

  • Windows clients: upgrade to version 2.0.63
  • Server installations: upgrade to version 2.0.62
  • Endpoint protection: enable cloud-delivered defenses in antivirus solutions
  • Authentication: implement phishing-resistant MFA for high-risk applications
  • Exposure management: deploy Microsoft Defender Vulnerability Management to scan for related weaknesses

Microsoft has published in-depth detection guidance and continues active surveillance of this campaign, ensuring defenders have the tools they need to detect and disrupt Marbled Dust’s operations.

More Articles & Posts