Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
As part of a cyber espionage attack campaign that began in April 2024, a threat actor with ties to Turkey took use of a zero-day security vulnerability in an Indian enterprise communication platform called Output Messenger.
The Microsoft Threat Intelligence team reported that these exploits have led to the gathering of relevant user data from targets in Iraq. According to previously noted Marbled Dust targeting criteria, the attack's targets are connected to the Kurdish armed forces stationed in Iraq.
The threat organization Marbled Dust (previously Silicon), also known as Cosmic Wolf, Sea Turtle, Teal Kurma, and UNC1326, has been blamed for the activities. Although Cisco Talos didn't identify assaults on public and private businesses in the Middle East and North Africa until two ye...

