Scworld
China-linked Bronze Butler Exploits Motex Lanscope Zero-Day Vulnerability
First seen 2 Dec 2025, 18:33 UTC
•
•68.7
Export
Article Content
Browse articles
China-linked cyber-espionage group Bronze Butler, also known as Tick, exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw was used to deploy an updated version of their Gokcpdoor malware to steal confidential information. The exploitation was observed by Sophos researchers in mid-2025 before a patch was released.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Critical Vulnerabilities Discovered in Mozilla Products
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats