216.73.216.6

BRONZE BUTLER exploits Japanese asset management software vulnerability

· Published 31/10/2025 02:16 · Modified 31/10/2025 09:23

Export JSON

Essential information

Published
31/10/2025 02:16
Modified
31/10/2025 09:23
Tags
2025-10-31 CVE-2025-61932 gokcpdoor havoc lanscope oaed loader zero-day
Related entities
1 intrusion sets (apt), 3 techniques (mitre), 3 malware, 1 others

Description

In mid-2025, a sophisticated campaign by the Chinese state-sponsored threat group BRONZE BUTLER (also known as Tick) exploited a vulnerability in Motex Endpoint Manager. The vulnerability, , allowed remote attackers to execute arbitrary commands with SYSTEM privileges. The threat actors used malware and the C2 framework for command and control. They also employed legitimate tools and services for lateral movement and data exfiltration, including goddi, remote desktop applications, and 7-Zip. Cloud storage services were accessed for potential data exfiltration. Organizations are advised to upgrade vulnerable servers and review internet-facing servers with components installed.

External references