Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers

As part of a cyber espionage attack campaign that began in April 2024, a threat actor with ties to Turkey took use of a zero-day security vulnerability in an Indian enterprise communication platform called Output Messenger.

The Microsoft Threat Intelligence team reported that these exploits have led to the gathering of relevant user data from targets in Iraq. According to previously noted Marbled Dust targeting criteria, the attack’s targets are connected to the Kurdish armed forces stationed in Iraq.

The threat organization Marbled Dust (previously Silicon), also known as Cosmic Wolf, Sea Turtle, Teal Kurma, and UNC1326, has been blamed for the activities. Although Cisco Talos didn’t identify assaults on public and private businesses in the Middle East and North Africa until two years later, the hacking team is thought to have been active since at least 2017.

It was also discovered to target Kurdish websites in the Netherlands read more about Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *