Microsoft Threat Intelligence has tracked the Türkiye-affiliated threat actor “Marbled Dust” actively exploiting a critical zero-day vulnerability-CVE-2025-27920-in the Output Messenger platform.
This multiplatform messaging application, used widely across the Middle East and Europe, was leveraged as a vector to compromise Kurdish military-linked targets in Iraq, highlighting a significant escalation in the technical sophistication and operational urgency of Marbled Dust’s cyber-espionage campaigns.
Technical Details of the Exploit
The exploited flaw is a directory traversal vulnerability resident in the Output Messenger Server Manager application.
Using this weakness, authenticated but malicious users could upload files-specifically, scripts and executables-directly into the Windows server’s startup directory.
By crafting a file upload request that manipulates the file path parameter, attackers bypassed built-in controls, depositing payloads like OMServerService.vbs and OMServerService.exe for execution upon system boot.
Upon gaining authenticated access-a process believed to involve DNS hijacking or typo-squatted domains to harvest credentials-Marbled Dust systematically implanted the backdoors using these upload capabilities.
The server payload, OMServerService.exe, is a GoLang-based malware, chosen for its portability and OS-agnosticism, and masqueraded as a legitimate component of Output Messenger.
This backdoor established communication with a hard-coded command-and-control domain (C2) at api.wordinfos[.]com, through which attackers directed exfiltration and further post-exploitation activity.
On the endpoint side, compromised clients had malicious binaries such as OMClientService.exe installed, which-once executed-performed C2 connectivity checks, system identification, and dynamic command execution received from the attackers, all through the same malicious domain.
Attack Chain Overview
After achieving initial access, Marbled Dust exploited the zero-day to persist on the host and move laterally within the network.

Their tactics included data collection from multiple users, credential theft, data exfiltration, and user impersonation, potentially allowing broad-spectrum espionage and operational disruption.
Notably, the attackers employed tools like Plink (command-line PuTTY) to establish external SSH tunnels for exfiltration, often compressing targeted files into transferable archives before extraction.
According to the Report, Microsoft, after discovering the exploit, promptly coordinated with Srimax (the Output Messenger developer) to release security patches-versions 2.0.63 for Windows clients and 2.0.62 for servers.
Users are strongly advised to upgrade immediately, enable cloud-delivered protection in Microsoft Defender, and apply advanced threat reduction rules.
Organizations are also urged to monitor for known IoCs, enable tamper protection, and configure automated investigation in their endpoint security solutions.
Marbled Dust, known for targeting government, military, telecommunications, and technology sectors conflicting with Turkish geopolitical interests, has previously executed DNS-level attacks and credential interception campaigns under aliases such as Sea Turtle and UNC1326.
Indicators of Compromise (IOCs)
| Indicator | Type | Description | First Seen | Last Seen |
|---|---|---|---|---|
| hxxps://api.wordinfos[.]com | Domain | C2 domain for GoLang backdoors | Apr 2024 | Ongoing |
| OMServerService.vbs/OM.vbs/OMServerService.exe | File Names | Dropped malicious scripts and executables | Apr 2024 | Ongoing |
| 1df959e4d2f48c4066fddcb5b3fd00b0b25ae44f350f5f35a86571abb2852e39 | SHA256 Hash | VBS script file hash | Apr 2024 | Ongoing |
| 2b7b65d6f8815dbe18cabaa20c01be655d8475fc429388a4541eff193596ae63 | SHA256 Hash | VBS script file hash | Apr 2024 | Ongoing |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates