logo

Chinese Houken Group Exploits Ivanti CSA Flaws to Deploy Linux Rootkits

ID: 513e4c63-7727-5945-a6d6-e315a79d7f52

STIX ID: report--513e4c63-7727-5945-a6d6-e315a79d7f52

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-07-02

Date Updated: 2026-04-19

Author: Mandvi

...
...

ANSSI uncovered a sophisticated September 2024 campaign by the group "Houken" (linked to UNC5174) exploiting three Ivanti CSA zero-days to gain RCE on exposed appliances, deploying webshells, a Linux kernel rootkit (sysinitd.ko), and backdoors to maintain persistence, conduct lateral movement, steal credentials, and exfiltrate sensitive emails across French government and critical sectors; the actors used a mix of bespoke and open-source tooling and diverse anonymization and VPS infrastructure (several IoCs provided).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.