Scworld
China-linked Hackers Exploit Lanscope Zero-Day to Deploy Gokcpdoor Malware
First seen 4 Nov 2025, 11:09 UTC
•
•51.1
Export
Article Content
Browse articles
Cyber-espionage group Bronze Butler, also known as Tick, has exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw was used to deploy an updated version of the Gokcpdoor malware to steal confidential information. The attacks were observed by Sophos researchers in mid-2025 before the vulnerability was patched.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
China-linked Bronze Butler Exploits Motex Lanscope Zero-Day Vulnerability
Critical Vulnerabilities Discovered in Mozilla Products
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques