Threat Intelligence, Vulnerability Management

New China-linked attacks involve zero-day Motex Lanscope bug exploitation

China Flag Made of Binary Code and Chinese Symbols on Red Backgr

Intrusions harnessing the critical request origin verification vulnerability in Motex Lanscope Endpoint Manager, tracked as CVE-2025-61932, as a zero-day have been launched by China-linked cyberespionage operation Bronze Butler, also known as Tick, to spread an updated Gokcpdoor malware over the past few months, reports BleepingComputer.

Multiplexed command-and-control communication support has been integrated into the latest version of the Gokcpdoor malware, which had a server-type iteration that enabled client connection listening on certain ports and a client-type variant that performed as a backdoor, an analysis from Sophos revealed. Other attacks involved the exploitation of the Havoc C2 framework.

However, all attacks were noted to have resulted in OAED Loader loading of the final payload and the use of DLL side-loading for covert injection into legitimate executables. Bronze Butler also exploited the goddi Active Directory dumper, 7-Zip file archiver, and Remote Desktop tool to pilfer data from LimeWire, Piping Server, and file.io.

Such a development comes after the recent inclusion of CVE-2025-61932 in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds