Full Breakdown
Cyber Espionage and Vulnerability Exploitation: The Rise of Tick and BADCANDY
11/2/2025, 5:43:25 AM
Tick Exploits Motex Lanscope Endpoint Manager
The cyber espionage group known as Tick, also referred to as Bronze Butler, has exploited a critical vulnerability in the Motex Lanscope Endpoint Manager, tracked as CVE-2025-61932. This vulnerability, which has a CVSS score of 9.3, allows remote attackers to execute arbitrary commands with SYSTEM privileges on affected systems. The Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) confirmed active exploitation of this flaw, which has been linked to the deployment of a backdoor known as Gokcpdoor. This backdoor enables attackers to maintain persistent access and execute malicious commands on compromised hosts.
Tick has a long history of targeting East Asian organizations, particularly in Japan, and has been active since at least 2006. The group previously exploited vulnerabilities in Japanese software, including a zero-day flaw in SKYSEA Client View in 2017. The recent campaign against Lanscope Endpoint Manager represents a continuation of Tick's strategy to exploit widely-used security and management software in Japan.
BADCANDY Web Shell Targets Cisco IOS XE Devices
In parallel, the Australian Signals Directorate (ASD) has reported ongoing attacks on unpatched Cisco IOS XE devices, where cybercriminals and state-sponsored actors are deploying a Lua-based web shell known as BADCANDY. This implant exploits the CVE-2023-20198 vulnerability, allowing unauthorized access to Cisco routers and switches. The vulnerability, which has a maximum CVSS score of 10.0, enables attackers to create highly privileged accounts without credentials.
Since July 2025, over 400 devices have been compromised, with more than 150 still infected as of late October. The BADCANDY implant allows attackers to execute root-level commands and maintain access through various persistence methods. Despite Cisco's patching efforts, the rapid exploitation of this vulnerability highlights the ongoing threat to network infrastructure.
Official Statements & Responses
Rafe Pilling, Director of Threat Intelligence at Sophos, noted, "We're aware of very targeted activity in Japan and believe the exploitation by Bronze Butler was limited to sectors aligned with their intelligence objectives." In response to the BADCANDY attacks, ASD has issued notifications urging immediate patching and incident response to mitigate the risks associated with the ongoing exploitation of Cisco devices.
Criticism & Opposition
Experts have raised concerns about the rapid exploitation of vulnerabilities following public disclosures. The exploitation of the Lanscope vulnerability and the BADCANDY web shell exemplifies how quickly threat actors can weaponize newly disclosed flaws. Organizations are urged to prioritize security measures, including patching and reviewing configurations to prevent unauthorized access.
Conflicting Reports & Gaps
While the JPCERT/CC and Sophos have confirmed the exploitation of the Lanscope vulnerability, the exact number of affected organizations remains unclear. Similarly, while ASD has reported a reduction in BADCANDY infections, fluctuations in infection rates suggest that attackers continue to exploit unpatched systems.
Verbatim Quotes
“Organizations upgrade vulnerable Lanscope servers as appropriate in their environments,” — Sophos TRU
“This activity shows that threat actors moved quickly to exploit this critical vulnerability in WSUS to collect valuable data from vulnerable organizations.” — Rafe Pilling, Director of Threat Intelligence at Sophos
“ASD attributes resurgences to unpatched systems left online, emphasizing that reboots alone won’t suffice without addressing the root vulnerability.” — ASD Statement
The ongoing activities of Tick and the exploitation of vulnerabilities like CVE-2025-61932 and CVE-2023-20198 underscore the critical need for organizations to enhance their cybersecurity defenses against sophisticated threat actors.
