NG Solution Team
Technology

Has a zero-day vulnerability in LANSCOPE Endpoint Manager been exploited to steal data?

A Chinese state-sponsored threat group, BRONZE BUTLER, has been exploiting a critical zero-day vulnerability in Motex LANSCOPE Endpoint Manager to target Japanese organizations and steal sensitive data. The flaw, identified as CVE-2025-61932, allows remote attackers to execute arbitrary code with SYSTEM privileges and affects LANSCOPE Endpoint Manager version 9.4.7.1 and earlier. Exploitation attempts began in April 2025, with the U.S. Cybersecurity and Infrastructure Security Agency adding the vulnerability to its Known Exploited Vulnerabilities Catalog in October 2025. Although the number of vulnerable devices is low, compromised systems could enable privilege escalation and lateral movement within networks. BRONZE BUTLER used Gokcpdoor, a sophisticated backdoor malware, and other tools for data exfiltration, demonstrating advanced operational security and targeting methods. Organizations with internet-facing LANSCOPE installations are urged to review their exposure, apply security updates, and monitor for connections to known command-and-control infrastructure.

Related posts

Could Apple’s First Foldable iPhone Feature Its Largest Battery Yet?

David Jones

How Much Have Samsung Galaxy Phone Prices Dropped in India?

David Jones

How is DataGlobal Hub revolutionizing global AI and data conferences with GDAI 2025?

David Jones

Leave a Comment

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy