China-Linked Tick Group Exploits Lanscope Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-7836 | Unauthenticated RCE in SKYSEA Client View Management Console SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in the processing of authentication on the TCP connection used with the management console program. An attacker with network reachability to that TCP service can send crafted authentication data that triggers remote code execution with no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). Successful exploitation gives the attacker full code execution on the console side, with high impact to confidentiality, integrity, and availability, and potential access to the managed-client inventory the console controls. Organizations running SKYSEA Client View Ver.11.221.03 or earlier are affected; the product is a client/IT-asset management suite deployed largely by Japanese organizations. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 14, 2025, indicating confirmed in-the-wild exploitation, and EPSS currently estimates a 19.4% probability of exploitation within 30 days. Do: Upgrade SKYSEA Client View to a fixed release later than Ver.11.221.03 as directed in Sky Group's security advisory (https://www.skygroup.jp/security-info/170308.html), and inventory any console running Ver.11.221.03 or older. Until patched, restrict access to the management console TCP port from untrusted network segments and review console servers for signs of compromise. CISA KEV requires applying vendor mitigations or discontinuing use within the BOD 22-01 timeline. | 9.8 | 19% | KEV PoC |
| largeon the order of tens of thousands of management console deployments (product has a cumulative licensed base of millions of endpoints, concentrated in Japan) | |
| CVE-2025-61932 | Unauthenticated RCE via spoofed packets in Motex LANSCOPE Endpoint Manager agents Motex LANSCOPE Endpoint Manager (On-Premises) — specifically its client program (MR) and detection agent (DA) components — fails to properly verify the source of incoming communications (CWE-940). An attacker who can reach a machine running the vulnerable agent over the network can send specially crafted packets and execute arbitrary code, with no privileges or user interaction required (CVSS 4.0: 9.3, critical, with high impact on confidentiality, integrity, and availability of the compromised endpoint). Organizations running the on-premises product, typically as agent software deployed across their managed endpoints, are affected. The flaw has been exploited as a zero-day in ongoing attacks, reportedly by the China-linked Tick group, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-22. No public proof-of-concept is known, but confirmed in-the-wild exploitation means patching should be treated as urgent. Do: Upgrade to the patched versions specified in Motex's security advisory (and the JPCERT coordination notice) as soon as possible; CISA KEV inclusion means U.S. federal agencies must patch or apply vendor mitigations per BOD 22-01. Until patched, restrict network access to the ports used for MR/DA agent communications and limit which network segments can send packets to agent hosts, since the flaw requires only network reachability. Given confirmed zero-day use by the China-linked Tick group, also hunt for signs of post-compromise lateral movement on endpoints running the agents. | 9.3 | 3% | KEV |
| masslikely 1M+ agent-installed endpoints across thousands of organizations, concentrated in Japan (exact install counts not published) |
Full article548 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 31, 2025Endpoint Security / Cyber Espionage
The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick.
The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges on on-premise versions of the program. JPCERT/CC, in an alert issued this month, said that it has confirmed reports of active abuse of the security defect to drop a backdoor on compromised systems.
Tick, also known as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, Stalker Taurus, and Swirl Typhoon (formerly Tellurium), is a suspected Chinese cyber espionage actor known for its extensive targeting of East Asia, specifically Japan. It's assessed to be active since at least 2006.
"We're aware of very targeted activity in Japan and believe the exploitation by Bronze Butler was limited to sectors aligned with their intelligence objectives," Rafe Pilling, director of threat intelligence at Sophos CTU, told The Hacker News. "Since this vulnerability is now publicly disclosed, other threat actors may seek to exploit it."
The sophisticated campaign, observed by Sophos, involved the exploitation of CVE-2025-61932 to deliver a known backdoor referred to as Gokcpdoor that can establish a proxy connection with a remote server and act as a backdoor to execute malicious commands on the compromised host.
"The 2025 variant discontinued support for the KCP protocol and added multiplexing communication using a third-party library [smux] for its C2 [command-and-control] communication," the Sophos Counter Threat Unit (CTU) said in a Thursday report.
The cybersecurity company said it detected two different types of Gokcpdoor serving distinct use-cases -
- A server type that listens for incoming client connections to enable remote access
- A client type that initiates connections to hard-coded C2 servers with the goal of setting up a covert communication channel
The attack is also characterized by the deployment of the Havoc post-exploitation framework on select systems, with the infection chains relying on DLL side-loading to launch a DLL loader named OAED Loader to inject the payloads.
Some of the other tools utilized in the attack to facilitate lateral movement and data exfiltration include goddi, an open-source Active Directory information dumping tool; Remote Desktop, for remote access through a backdoor tunnel; and 7-Zip.
The threat actors have also been found to access cloud services such as io, LimeWire, and Piping Server via the web browser during remote desktop sessions in an effort to exfiltrate the harvested data.
This is not the first time Tick has been observed leveraging a zero-day flaw in its attack campaigns. In October 2017, Sophos-owned Secureworks detailed the hacking group's exploitation of a then-unpatched remote code execution vulnerability (CVE-2016-7836) in SKYSEA Client View, a Japanese IT asset management software, to compromise machines and steal data.
"Organizations upgrade vulnerable Lanscope servers as appropriate in their environments," Sophos TRU said. "Organizations should also review internet-facing Lanscope servers that have the Lanscope client program (MR) or detection agent (DA) installed to determine if there is a business need for them to be publicly exposed."
(The story was updated after publication to include a response from Sophos.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html