Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign Security Patch Release

Motex Lanscope exploitation, backdoor activity, and remediation

Updated 06.11.2025 04:00
Case score 64
Members 3 First seen 23.10.2025 08:37 Latest activity 06.11.2025 04:00

Overview

Attackers are exploiting **CVE-2025-61932** in **Motex Lanscope Endpoint Manager** on-premises systems to run commands with **SYSTEM** privileges and plant backdoors. **JPCERT/CC** confirmed active abuse, and the available evidence ties the activity to **Tick/Bronze Butler** tooling such as **Gokcpdoor**, **Havoc**, **DLL side-loading**, and **OAED Loader**. **Motex** released fixed builds for the affected **Client program** and **Detection Agent** versions, while **CISA** added the flaw to **KEV** and set a **November 12, 2025** remediation deadline for Federal Civilian Executive Branch agencies. Available evidence does not quantify the full reach or identify every affected organization.
Latest development Open development history 2 earlier developments Sophos attributes Lanscope zero-day exploitation to Bronze Butler Sophos said Bronze Butler, also tracked as Tick, RedBaldKnight, Stalker Panda, and Swirl Typhoon, exploited CVE-2025-61932 as a zero-day in Lanscope in mid-2025 to breach organizations in Japan, deploy Gokcpdoor or Havoc, and use OAED, 7-Zip, remote desktop, file.io, and LimeWire for lateral movement and exfiltration; CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog, and JPCERT/CC said domestic organizations may have been affected since as early as April 2025.
  1. Earlier development

    Motex discloses CVE-2025-61932 and releases a fix

    Motex disclosed CVE-2025-61932 in Lanscope and released a fix for the on-premises issue; the cloud version was not affected.

  2. Earlier development

    Tick exploits CVE-2025-61932 in Motex Lanscope Endpoint Manager

    Tick is exploiting CVE-2025-61932 in on-premise Motex Lanscope Endpoint Manager systems to execute arbitrary commands with SYSTEM privileges and drop the Gokcpdoor backdoor. JPCERT/CC confirms active abuse of the flaw, and Sophos ties the activity to a cyber espionage campaign associated with Tick, also known as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, Stalker Taurus, and Swirl Typhoon.

Signals

Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

6 listed

Malware & tooling context

1 families · 4 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Motex Lanscope Endpoint Manager actively exploited source verification RCE (CVE-2025-61932)
Updated 23.10.2025 08:37 Lead Contribution 61
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CVE-2025-61932** is a critical **Motex Lanscope Endpoint Manager** vulnerability that was **actively exploited** as a **zero-day** by **Tick/BRONZE BUTLER** against **on-premises** systems. The flaw can let attackers run **arbitrary commands with SYSTEM privileges**, and **JPCERT/CC** confirmed reports of active abuse to drop a backdoor on compromised hosts. Sophos observed the campaign using **Gokcpdoor**, **Havoc**, and **DLL side-loading** with **OAED Loader** to maintain access, move laterally, and exfiltrate data. **CISA** added **CVE-2025-61932** to the **Known Exploited Vulnerabilities** catalog, and fixes are available for affected **Client program** and **Detection Agent** releases.

Campaign Tick Motex Lanscope CVE-2025-61932 exploitation campaign
Updated 31.10.2025 15:26 Scoring Support Contribution 3
Objective Espionage Campaign Active

A **Tick (Bronze Butler)** campaign exploited **CVE-2025-61932** in **Motex Lanscope Endpoint Manager** to deploy **Gokcpdoor** and gain remote access to compromised hosts. The operation enabled **SYSTEM**-level command execution, covert proxying, and follow-on tooling for **lateral movement** and **data exfiltration**. **JPCERT/CC** confirmed active abuse, showing the campaign was already being used against **on-premise** deployments.

Security Patch Release Motex security patch release for CVE-2025-61932
Updated 06.11.2025 04:00 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

**Motex** released a fix for **CVE-2025-61932** in **Lanscope**, addressing a **critical** on-premises flaw that had already been exploited as a **zero-day**. The patch narrows the exposed scope because **cloud deployments** are unaffected. The update matters because Lanscope is widely used in **Japan**, including by major listed and financial institutions.