The Chinese state-sponsored threat group BRONZE BUTLER (also known as Tick) exploited a zero-day vulnerability, CVE-2025-61932, in the Motex LANSCOPE Endpoint Manager software to gain SYSTEM-level control over targeted systems. This vulnerability allows remote attackers to execute arbitrary commands with elevated privileges, enabling initial access, privilege escalation, and lateral movement within compromised networks. The campaign was observed in mid-2025, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding the vulnerability to its Known Exploited Vulnerabilities Catalog on October 22, 2025. JPCERT/CC also issued a public notice regarding the issue.
BRONZE BUTLER leveraged the Gokcpdoor malware in this operation, which in its 2025 variant introduced multiplexing communication for command and control (C2) and discontinued support for the KCP protocol. The malware was deployed in both server and client configurations, enabling remote access and control over compromised assets. While the number of vulnerable internet-facing devices was reported to be low, the exploitation of internal systems posed significant risks for data theft and further compromise within affected organizations, particularly those using Japanese asset management software.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On October 30, 2025, Sophos publicly detailed the campaign, attributing the activity to Bronze Butler and describing updated Gokcpdoor variants, OAED Loader, Havoc C2 use, lateral movement, exfiltration methods, and related indicators of compromise. The report also recommended upgrading vulnerable LANSCOPE servers and reviewing exposure of internet-facing components.
On October 22, 2025, CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities catalog, and JPCERT/CC published a notice the same day. CISA directed U.S. federal agencies to remediate the flaw by November 12, 2025.
On October 20, 2025, Motex disclosed CVE-2025-61932 as an emergency-severity flaw in LANSCOPE Endpoint Manager 9.4.7.2 and earlier and released patches. The vendor said the issue affects on-premises deployments and that the cloud version is not impacted.
In mid-2025, Sophos CTU observed Bronze Butler exploiting CVE-2025-61932 as a zero-day to gain remote code execution with SYSTEM privileges and steal confidential information. The intrusion chain deployed updated Gokcpdoor malware, and in some cases Havoc C2, with OAED Loader and DLL sideloading used to run payloads inside legitimate executables.
JPCERT/CC indicated domestic victims may date back to April 2025, suggesting Bronze Butler (Tick) began exploiting the Motex LANSCOPE Endpoint Manager flaw CVE-2025-61932 by then. The attacks targeted on-premises, internet-exposed Lanscope servers in Japan for cyber-espionage and data theft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcenews.sophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.