HomeSecurityTick Group from China Exploits Lanscope Zero-Day

Tick ​​Group from China Exploits Lanscope Zero-Day

A newly disclosed critical zero-day vulnerability in Motex Lanscope Endpoint Manager is being exploited by a cyberespionage group known as Tick. The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges on locally installed versions of the program.

See also: Critical zero-day in Windows Agere Modem actively exploited

Tick ​​zero-day

JPCERT /CC, in an advisory issued this month, confirmed reports of active exploitation of the security flaw to install a backdoor on compromised systems. Tick, also known as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, Stalker Taurus, and Swirl Typhoon (formerly Tellurium), is a suspected Chinese cyberespionage actor known for extensively targeting East Asia, especially Japan. It has been active since at least 2006.

The sophisticated campaign, observed by Sophos, involved exploiting CVE-2025-61932 to deliver a known backdoor referred to as Gokcpdoor, which can establish a proxy connection to a remote server and act as a backdoor to execute malicious commands on the compromised computer.

“The 2025 variant dropped support for the KCP protocol and added multi-stream communication using a third-party library [smux] for C2 [command-and-control] communication,” the Sophos Counter Threat Unit (CTU) said in a report on Thursday. The cybersecurity firm identified two different variants of Gokcpdoor that serve different uses:

See also: Zero-day exploit in Windows Remote Access Connection Manager

Tick ​​Group from China Exploits Lanscope Zero-Day

1. A type of server that listens for incoming client connections to allow remote access.

2. A type of client that initiates connections to programmed C2 servers with the goal of establishing a covert communication channel.

The attack is also characterized by the deployment of the Havoc post-exploit framework on select systems, with infection chains relying on sideloading DLLs to launch a DLL loader named OAED Loader to inject the payloads. Other tools used in the attack to facilitate sideloading and data extraction include goddi, an open source tool for dumping Active Directory information, Remote Desktop for remote access via a backdoor tunnel, and 7-Zip.

Threat actors have also been found to access cloud services such as io, LimeWire, and Piping Server via the browser during remote desktop sessions in an attempt to extract the collected data. This is not the first time Tick has been observed exploiting a zero-day vulnerability in its offensive campaigns.

See also: Zimbra: Zero-day used to target Brazilian military

Tick ​​Group from China Exploits Lanscope Zero-Day

In October 2017, Secureworks, owned by Sophos, analyzed the hacking group's exploitation of a then-unpatched remote code execution vulnerability (CVE-2016-7836) in SKYSEA Client View, a Japanese IT asset management software, to compromise machines and steal data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS