Motex Lanscope exploitation, backdoor activity, and remediation
Case score 64
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 64
- Main story score
- 61
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Anchors the on-premises Lanscope zero-day exploitation and active abuse. main
- Campaign Confirms the same CVE was used in a Tick/Bronze Butler campaign with backdoor deployment. contributes
- Security Patch Release Provides Motex's fix and the affected-version scope for the same CVE. context
Overview
Latest development Open development history Sophos attributes Lanscope zero-day exploitation to Bronze Butler Sophos said Bronze Butler, also tracked as Tick, RedBaldKnight, Stalker Panda, and Swirl Typhoon, exploited CVE-2025-61932 as a zero-day in Lanscope in mid-2025 to breach organizations in Japan, deploy Gokcpdoor or Havoc, and use OAED, 7-Zip, remote desktop, file.io, and LimeWire for lateral movement and exfiltration; CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog, and JPCERT/CC said domestic organizations may have been affected since as early as April 2025.
-
Motex discloses CVE-2025-61932 and releases a fix
Motex disclosed CVE-2025-61932 in Lanscope and released a fix for the on-premises issue; the cloud version was not affected.
-
Tick exploits CVE-2025-61932 in Motex Lanscope Endpoint Manager
Tick is exploiting CVE-2025-61932 in on-premise Motex Lanscope Endpoint Manager systems to execute arbitrary commands with SYSTEM privileges and drop the Gokcpdoor backdoor. JPCERT/CC confirms active abuse of the flaw, and Sophos ties the activity to a cyber espionage campaign associated with Tick, also known as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, Stalker Taurus, and Swirl Typhoon.