By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
Tech News

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

By Viral Trending Content 4 Min Read
Share
SHARE

Oct 31, 2025Ravie LakshmananEndpoint Security / Cyber Espionage

The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick.

The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges on on-premise versions of the program. JPCERT/CC, in an alert issued this month, said that it has confirmed reports of active abuse of the security defect to drop a backdoor on compromised systems.

Tick, also known as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, Stalker Taurus, and Swirl Typhoon (formerly Tellurium), is a suspected Chinese cyber espionage actor known for its extensive targeting of East Asia, specifically Japan. It’s assessed to be active since at least 2006.

DFIR Retainer Services

“We’re aware of very targeted activity in Japan and believe the exploitation by Bronze Butler was limited to sectors aligned with their intelligence objectives,” Rafe Pilling, director of threat intelligence at Sophos CTU, told The Hacker News. “Since this vulnerability is now publicly disclosed, other threat actors may seek to exploit it.”

The sophisticated campaign, observed by Sophos, involved the exploitation of CVE-2025-61932 to deliver a known backdoor referred to as Gokcpdoor that can establish a proxy connection with a remote server and act as a backdoor to execute malicious commands on the compromised host.

“The 2025 variant discontinued support for the KCP protocol and added multiplexing communication using a third-party library [smux] for its C2 [command-and-control] communication,” the Sophos Counter Threat Unit (CTU) said in a Thursday report.

The cybersecurity company said it detected two different types of Gokcpdoor serving distinct use-cases –

  • A server type that listens for incoming client connections to enable remote access
  • A client type that initiates connections to hard-coded C2 servers with the goal of setting up a covert communication channel

The attack is also characterized by the deployment of the Havoc post-exploitation framework on select systems, with the infection chains relying on DLL side-loading to launch a DLL loader named OAED Loader to inject the payloads.

Some of the other tools utilized in the attack to facilitate lateral movement and data exfiltration include goddi, an open-source Active Directory information dumping tool; Remote Desktop, for remote access through a backdoor tunnel; and 7-Zip.

CIS Build Kits

The threat actors have also been found to access cloud services such as io, LimeWire, and Piping Server via the web browser during remote desktop sessions in an effort to exfiltrate the harvested data.

This is not the first time Tick has been observed leveraging a zero-day flaw in its attack campaigns. In October 2017, Sophos-owned Secureworks detailed the hacking group’s exploitation of a then-unpatched remote code execution vulnerability (CVE-2016-7836) in SKYSEA Client View, a Japanese IT asset management software, to compromise machines and steal data.

“Organizations upgrade vulnerable Lanscope servers as appropriate in their environments,” Sophos TRU said. “Organizations should also review internet-facing Lanscope servers that have the Lanscope client program (MR) or detection agent (DA) installed to determine if there is a business need for them to be publicly exposed.”

(The story was updated after publication to include a response from Sophos.)

You Might Also Like

AI One Raises $11M to Help Companies Turn Business Context Into Decision-Ready AI

Alienware Aurora Gaming Desktop Review: Great Value

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

What opportunities exist for experts in Ireland’s offshore wind sector?

Gemini 3 vs Claude vs Codex, IDE and CLI Features Explained

TAGGED: cyber espionage, Cyber Security, Cybersecurity, data breach, endpoint security, Internet, Malware, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Devastation on repeat: How climate change is worsening Pakistan's deadly floods
Next Article French justice minister’s prison visit to Sarkozy sparks legal complaint by lawyers
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Colorado developer pays $15.14 million for 12.6 acres near Park Meadows Mall
Business
First For The Nation: Texas Invests $10M In Bitcoin, Leading State Treasury Move
Crypto
Explosive Ukraine peace agreement shocks Europe
World News
AI One Raises $11M to Help Companies Turn Business Context Into Decision-Ready AI
Tech News
Sweden’s Klarna announces KlarnaUSD stablecoin, set to go live on Tempo
Crypto
Alienware Aurora Gaming Desktop Review: Great Value
Tech News
EU must ‘stand by the promises made’ on digital rules, Vestager tells Euronews
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Colorado developer pays $15.14 million for 12.6 acres near Park Meadows Mall

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Colorado developer pays $15.14 million for 12.6 acres near Park Meadows Mall
November 25, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?