Threat Advisory

BRONZE BUTLER APT Leverages LANSCOPE Zero-Day for Targeted Japanese Network Breaches

Threat: Vulnerability/Malware
Threat Actor Name: Bronze Butler
Threat Actor Type: State-Sponsored
Targeted Region: Japan
Alias: G0060, Stalker Panda, Temp.Tick, Stalker Taurus, Tick, Hive0076, RedBaldNight, CTG-2006
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Bronze Butler, a long-standing cyber-espionage group, has been observed exploiting a critical vulnerability in a popular Japanese asset management software to compromise corporate networks. The threat actor targeted organizations in Japan, aiming to gain unauthorized access, conduct reconnaissance, and exfiltrate sensitive business information. This campaign highlights the groups continued focus on Japanese entities and its strategic use of software supply chains and localized tools to maintain covert access.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Bronze Butler, a long-standing cyber-espionage group, has been observed exploiting a critical vulnerability in a popular Japanese asset management software to compromise corporate networks. The threat actor targeted organizations in Japan, aiming to gain unauthorized access, conduct reconnaissance, and exfiltrate sensitive business information. This campaign highlights the groups continued focus on Japanese entities and its strategic use of software supply chains and localized tools to maintain covert access.[emaillocker id="1283"]

The attack centers on a critical remote code execution flaw, CVE-2025-61932, affecting LANSCOPE Endpoint Manager, which allows adversaries to run commands with SYSTEM-level privileges on exposed servers. After exploiting the vulnerability, the attackers established persistence by deploying a custom backdoor known as Gokcpdoor, observed in both server-type and client-type variants; the server variant acted as a listener while the client variant connected outbound to predefined command-and-control infrastructure. An OAED Loader was used to inject malicious code into legitimate executables, complicating detection and analysis. Additional tooling included credential and directory-dumping utilities, remote desktop access through tunneled connections, and 7-Zip for compressing and exfiltrating stolen files. In some cases, the attackers transitioned to using the Havoc C2 framework, enabling more flexible post-exploitation control. Compromised environments also showed evidence of data staging and use of cloud-based storage channels to move data outside the network.

It is being actively exploited and allows full code execution with elevated privileges, so organizations running the affected software must treat this as a critical incident. Remediation requires immediate verification of whether the on-premises endpoint or asset management solution is deployed, identification of exposed endpoints, and patching to a secure version as published by the vendor. At the same time, organizations should review network exposure, audit logs for anomalous inbound traffic, and strengthen endpoint monitoring to detect any signs of compromise. Failure to respond swiftly may lead to deep network penetration, persistent access by threat actors, and potential data exfiltration.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1190 Exploit Public-Facing Application -
T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Persistence T1543.003 Create or Modify System Process Windows Service
Privilege Escalation T1068 Exploitation for Privilege Escalation -
Credential Access T1003.001 OS Credential Dumping LSASS Memory
Discovery T1087.001 Account Discovery Local Account
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Collection T1005 Data from Local System -
T1074.001 Data Staged Local Data Staging
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu