China-linked 'Bronze Butler' Exploits Lanscope Zero-Day (CVE-2025-61932)
CriticalWhat happened
The cyber-espionage group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager to deploy an updated version of their Gokcpdoor malware, enabling unauthorized remote code execution with SYSTEM privileges.
Who is affected
Organizations using Motex Lanscope Endpoint Manager versions 9.4.7.2 and earlier are at risk, particularly those in sectors targeted by 'Bronze Butler'.
Why it matters
Exploitation of this vulnerability allows attackers to execute arbitrary code remotely, potentially leading to data theft, system compromise, and further network infiltration.
How it could have been prevented
Timely application of security patches released by Motex on October 20, 2025, and regular monitoring for unusual network activity.
Relevant professional terms
- Zero-Day Vulnerability
- A software flaw unknown to the vendor, exploited by attackers before a fix is available.
- Remote Code Execution (RCE)
- The ability of an attacker to run arbitrary code on a target system remotely.
Recommended reading: Sophos Reports on Bronze Butler Exploiting Lanscope Zero-Day
