Turkish hackers, who are mainly involved in cyber espionage, exploited a previously unknown vulnerability (zero-day) to launch attacks against users of the Output Messenger. The main targets were linked to the Kurdish army in Iraq.

Microsoft Threat Intelligence experts who spotted this activity also discovered the vulnerability used in the attacks ( CVE-2025-27920 ). This is a “ directory traversal ” vulnerability, which allows access to files outside the intended folder, or even placing malicious files in the server’s startup folder.
As the Output Messenger developer, Srimax , explains , the vulnerability has been fixed since December, with version V2.0.63 . However, its exploitation allows unauthorized attackers to gain access to sensitive files such as system settings, user personal data, or even source code . This type of access can lead to even more serious breaches, such as remote execution of malicious code .
See also: Vulnerability in VMware Tools allows file compromise
Microsoft revealed that the Turkish group – also known as Sea Turtle, SILICON and UNC1326 – is targeting users who have not installed the necessary updates, in order to infiltrate their systems via the Output Messenger Server Manager and install malware.
Once they manage to breach the server, hackers, which Microsoft calls “Marbled Dust,” can steal confidential information, gain access to internal communications, spoof user identities , and infiltrate critical infrastructure, causing significant operational disruptions.
While there is currently no clear indication of exactly how Marbled Dust managed to obtain login credentials, analysts believe the attackers likely used techniques such as DNS hijacking or typo-squatted domainsto steal and reuse login credentials. These methods have also been identified in previous attacks by the same group.
After gaining access to the victims’ systems, the cybercriminals installed a malicious program called OMServerService.exe, which acted as a “backdoor.” This program maintained contact with a remote command and control server (api.wordinfos[.]com), which was under the full control of the attackers. Through this connection, the perpetrators were able to collect additional datain order to identify and categorize their targets.
See also: What are elevation of privilege vulnerabilities and how to protect yourself
In one of the confirmed cases, the Output Messenger client on a victim's device contacted an IP address linked to Turkish hackers Marbled Dust. This communication was reportedly related to the data upload, which took place shortly after the malware was instructed to collect specific files and compress them into a RAR archive.
The Marbled Dust group mainly targets regions of Europe and the Middle East , with key targets being organizations in the sectors telecommunications and technology , while government structures that oppose Turkey's policies are also in the crosshairs

To penetrate networks, attackers look for vulnerabilities in devices that are accessible via the Internet. At the same time, they leverage their access to already compromised DNS servers, changing settings, resulting in diverting traffic and stealing credentials through man-in-the-middle.
Microsoft noted that this latest attack indicates a significant enhancement of Marbled Dust. The use of a zero-day vulnerability in Output Messenger demonstrates superior technical expertise and may reflect either heightened operational priorities or increasing pressure to achieve specific strategic goals.
What are the latest techniques for dealing with Zero-Day vulnerabilities?
One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Chinese hackers exploit SAP NetWeaver vulnerability
Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.
Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.
Source: www.bleepingcomputer.com
