Active Output Messenger 0‑Day Breach Used to Drop Malware on Targeted Systems

Microsoft Threat Intelligence has tracked the Türkiye-affiliated threat actor “Marbled Dust” actively exploiting a critical zero-day vulnerability-CVE-2025-27920-in the Output Messenger platform.

This multiplatform messaging application, used widely across the Middle East and Europe, was leveraged as a vector to compromise Kurdish military-linked targets in Iraq, highlighting a significant escalation in the technical sophistication and operational urgency of Marbled Dust’s cyber-espionage campaigns.

Technical Details of the Exploit

The exploited flaw is a directory traversal vulnerability resident in the Output Messenger Server Manager application.

Using this weakness, authenticated but malicious users could upload files-specifically, scripts and executables-directly into the Windows server’s startup directory.

By crafting a file upload request that manipulates the file path parameter, attackers bypassed built-in controls, depositing payloads like OMServerService.vbs and OMServerService.exe for execution upon system boot.

Upon gaining authenticated access-a process believed to involve DNS hijacking or typo-squatted domains to harvest credentials-Marbled Dust systematically implanted the backdoors using these upload capabilities.

The server payload, OMServerService.exe, is a GoLang-based malware, chosen for its portability and OS-agnosticism, and masqueraded as a legitimate component of Output Messenger.

This backdoor established communication with a hard-coded command-and-control domain (C2) at api.wordinfos[.]com, through which attackers directed exfiltration and further post-exploitation activity.

On the endpoint side, compromised clients had malicious binaries such as OMClientService.exe installed, which-once executed-performed C2 connectivity checks, system identification, and dynamic command execution received from the attackers, all through the same malicious domain.

Attack Chain Overview

After achieving initial access, Marbled Dust exploited the zero-day to persist on the host and move laterally within the network.

 0‑Day Breach
 The Marbled Dust attack chain

Their tactics included data collection from multiple users, credential theft, data exfiltration, and user impersonation, potentially allowing broad-spectrum espionage and operational disruption.

Notably, the attackers employed tools like Plink (command-line PuTTY) to establish external SSH tunnels for exfiltration, often compressing targeted files into transferable archives before extraction.

According to the Report, Microsoft, after discovering the exploit, promptly coordinated with Srimax (the Output Messenger developer) to release security patches-versions 2.0.63 for Windows clients and 2.0.62 for servers.

Users are strongly advised to upgrade immediately, enable cloud-delivered protection in Microsoft Defender, and apply advanced threat reduction rules.

Organizations are also urged to monitor for known IoCs, enable tamper protection, and configure automated investigation in their endpoint security solutions.

Marbled Dust, known for targeting government, military, telecommunications, and technology sectors conflicting with Turkish geopolitical interests, has previously executed DNS-level attacks and credential interception campaigns under aliases such as Sea Turtle and UNC1326.

Indicators of Compromise (IOCs)

IndicatorTypeDescriptionFirst SeenLast Seen
hxxps://api.wordinfos[.]comDomainC2 domain for GoLang backdoorsApr 2024Ongoing
OMServerService.vbs/OM.vbs/OMServerService.exeFile NamesDropped malicious scripts and executablesApr 2024Ongoing
1df959e4d2f48c4066fddcb5b3fd00b0b25ae44f350f5f35a86571abb2852e39SHA256 HashVBS script file hashApr 2024Ongoing
2b7b65d6f8815dbe18cabaa20c01be655d8475fc429388a4541eff193596ae63SHA256 HashVBS script file hashApr 2024Ongoing

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories