EXECUTIVE SUMMARY:
Bronze Butler, a long-standing cyber-espionage group, has been observed exploiting a critical vulnerability in a popular Japanese asset management software to compromise corporate networks. The threat actor targeted organizations in Japan, aiming to gain unauthorized access, conduct reconnaissance, and exfiltrate sensitive business information. This campaign highlights the groups continued focus on Japanese entities and its strategic use of software supply chains and localized tools to maintain covert access.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Bronze Butler, a long-standing cyber-espionage group, has been observed exploiting a critical vulnerability in a popular Japanese asset management software to compromise corporate networks. The threat actor targeted organizations in Japan, aiming to gain unauthorized access, conduct reconnaissance, and exfiltrate sensitive business information. This campaign highlights the groups continued focus on Japanese entities and its strategic use of software supply chains and localized tools to maintain covert access.[emaillocker id="1283"]
The attack centers on a critical remote code execution flaw, CVE-2025-61932, affecting LANSCOPE Endpoint Manager, which allows adversaries to run commands with SYSTEM-level privileges on exposed servers. After exploiting the vulnerability, the attackers established persistence by deploying a custom backdoor known as Gokcpdoor, observed in both server-type and client-type variants; the server variant acted as a listener while the client variant connected outbound to predefined command-and-control infrastructure. An OAED Loader was used to inject malicious code into legitimate executables, complicating detection and analysis. Additional tooling included credential and directory-dumping utilities, remote desktop access through tunneled connections, and 7-Zip for compressing and exfiltrating stolen files. In some cases, the attackers transitioned to using the Havoc C2 framework, enabling more flexible post-exploitation control. Compromised environments also showed evidence of data staging and use of cloud-based storage channels to move data outside the network.
It is being actively exploited and allows full code execution with elevated privileges, so organizations running the affected software must treat this as a critical incident. Remediation requires immediate verification of whether the on-premises endpoint or asset management solution is deployed, identification of exposed endpoints, and patching to a secure version as published by the vendor. At the same time, organizations should review network exposure, audit logs for anomalous inbound traffic, and strengthen endpoint monitoring to detect any signs of compromise. Failure to respond swiftly may lead to deep network penetration, persistent access by threat actors, and potential data exfiltration.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1190 | Exploit Public-Facing Application | - |
| T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain | |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | - |
| Credential Access | T1003.001 | OS Credential Dumping | LSASS Memory |
| Discovery | T1087.001 | Account Discovery | Local Account |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Collection | T1005 | Data from Local System | - |
| T1074.001 | Data Staged | Local Data Staging | |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]