Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Cyber Attacks

Turkish Cyber Espionage Campaign Leverages Zero-Day in Output Messenger

May 13, 2025
Reading Time: 1 min read
Turkish Cyber Espionage Campaign Leverages Zero-Day in Output Messenger

A Turkish-affiliated threat actor, identified as “Marbled Dust,” has been exploiting a zero-day vulnerability in the Output Messenger application to conduct cyber espionage. The attacks, which reportedly began in April 2024, have primarily targeted entities in Europe and the Middle East, with a specific focus on Kurdish military personnel in Iraq and organizations with interests conflicting with the Turkish government. This campaign highlights a significant escalation in the group’s technical capabilities and operational urgency.

The core of the espionage activity revolves around a directory traversal vulnerability, tracked as CVE-2025-27920, found in Output Messenger, an enterprise communication platform developed by Indian company Srimax. Marbled Dust utilized techniques such as DNS hijacking to gain initial access to the Output Messenger Server Manager application. Subsequently, they exploited the zero-day flaw to upload malicious files, including GoLang-based backdoors, to the server’s startup directory. This allowed the attackers to steal sensitive data, impersonate users, and potentially disrupt operations.

In response to the threat, Microsoft Threat Intelligence notified Srimax, the developer of Output Messenger. Srimax has since released a software update (version 2.0.63) to address CVE-2025-27920 and a second cross-site scripting (XSS) vulnerability (CVE-2025-27921), although there is no evidence the latter was exploited. Both Microsoft and Srimax urge all Output Messenger users to upgrade to the latest version immediately to protect against these attacks. Security experts recommend implementing robust security measures, including enabling cloud-delivered protection and utilizing comprehensive vulnerability management systems.

Tags: CVE-2025-27920Cyber EspionageCyberSecuritydata-breachhackingKurdishMarbled DustMicrosoft Threat Intelligencenational securityOutput MessengerSoftware VulnerabilitySrimaxTurkish HackersZero-Day Vulnerability
ShareTweet

Related Posts

Israeli Drone Director Vered Haimovich Targeted in Hacktivist Leak
Cyber Attacks

Israeli Drone Director Vered Haimovich Targeted in Hacktivist Leak

April 8, 2026
Dubai International Airport Suffers Alleged Data Breach
Cyber Attacks

Dubai International Airport Suffers Alleged Data Breach

March 31, 2026
Lockheed Martin Employees doxed in Handala Hack Campaign
Cyber Attacks

Lockheed Martin Employees doxed in Handala Hack Campaign

March 26, 2026
Vahid Online Doxxed and Breached by Handala Hack Team
Cyber Attacks

Vahid Online Doxxed and Breached by Handala Hack Team

March 17, 2026
Israel National Security Institute Suffers Data Breach by Handala
Cyber Attacks

Israel National Security Institute Suffers Data Breach by Handala

March 17, 2026
NoName057(16) Targets Shas Party and Israeli Councils in DDoS Wave
Cyber Attacks

NoName057(16) Targets Shas Party and Israeli Councils in DDoS Wave

March 16, 2026
Next Post
Alleged Breach of Everest Bank Customer Database

Alleged Breach of Everest Bank Customer Database

China Census Database Allegedly Leaked with 92 Million Records

China Census Database Allegedly Leaked with 92 Million Records

Recommended Stories

Alleged Data Breach Exposes Millions of Social Security Administration Records

Alleged Data Breach Exposes Millions of Social Security Administration Records

May 20, 2025
Extensive Personal Data Leak Reported in France

Extensive Personal Data Leak Reported in France

January 14, 2025
MecMatica Italy Data Breach: Sarcoma Ransomware Leak Details

MecMatica Italy Data Breach: Sarcoma Ransomware Leak Details

January 20, 2026

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?