logo

China-linked hackers exploited Lanscope flaw as a zero-day in attacks

ID: b0a65070-aaca-5036-a6e4-882c81eaad6c

STIX ID: report--b0a65070-aaca-5036-a6e4-882c81eaad6c

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-11-01

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

China-linked Bronze Butler (Tick) exploited a Motex Lanscope Endpoint Manager zero-day (CVE-2025-61932) in mid-2025 to deploy an updated Gokcpdoor backdoor that provides SYSTEM-level remote code execution and multiplexed C2; the attacks used OAED Loader and DLL sideloading for evasion and employed tools like an Active Directory dumper, RDP, and 7-Zip for data collection and exfiltration. Motex released a patch on 2025-10-20 and CISA added the flaw to its KEV catalog with a November 12, 2025 mitigation deadline; Sophos observed active exploitation and recommends immediate patching as no mitigations exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.