Chinese Houken Group Exploits Ivanti CSA Flaws to Deploy Linux Rootkits
ID: 513e4c63-7727-5945-a6d6-e315a79d7f52
STIX ID: report--513e4c63-7727-5945-a6d6-e315a79d7f52
Feed Name: Cyber Press
ANSSI uncovered a sophisticated September 2024 campaign by the group "Houken" (linked to UNC5174) exploiting three Ivanti CSA zero-days to gain RCE on exposed appliances, deploying webshells, a Linux kernel rootkit (sysinitd.ko), and backdoors to maintain persistence, conduct lateral movement, steal credentials, and exfiltrate sensitive emails across French government and critical sectors; the actors used a mix of bespoke and open-source tooling and diverse anonymization and VPS infrastructure (several IoCs provided).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
