Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actorExploits 1 CVE

OAED Loader

OAED Loader is a DLL loader used in intrusion chains attributed to the China-linked cyber-espionage group Tick, also known as Bronze Butler. In the reported mid-2025 campaigns exploiting Motex LANSCOPE Endpoint Manager vulnerability CVE-2025-61932, OAED Loader was used in all observed instances to load the final payload and inject it into legitimate executables via DLL side-loading for evasion. The malware injects a payload into a legitimate executable according to its embedded configuration and was observed with both Gokcpdoor and, in some cases, Havoc-related samples to complicate execution flow. The broader activity targeted LANSCOPE environments and was associated with theft of confidential information, with post-exploitation activity including Active Directory data collection, remote access, and exfiltration through cloud services. No standalone infection vector, persistence mechanism, or specific OAED Loader file indicators were provided in the content beyond its role as a DLL loader and payload injector in this campaign.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-61932RCE in MOTEX LANSCOPE Endpoint Manager On-Premises MR/DAExploited in the wild

China-linked cyber-espionage actors tracked as 'Bronze Butler' (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day... The flaw exploited in these attacks is CVE-2025-61932, a critical request origin verification flaw impacting Motex Lanscope Endpoint Manager versions 9.4.7.2 and earlier. It enables unauthenticated attackers to execute arbitrary code on the target with SYSTEM privileges via specially crafted packets.

via bleeping computerbleepingcomputer.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BRONZE BUTLER

Some Gokcpdoor and Havoc samples used the OAED Loader malware... This malware injects a payload into a legitimate executable according to its embedded configuration.

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1620Reflective Code LoadingEvidence1
TacticStealth

all attacks were noted to have resulted in OAED Loader loading of the final payload

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.