UNC5174 Exploits Ivanti CSA Zero-Days in “Houken” Campaign (Campaign)
ID: 01ecbe55-af10-56eb-ab6c-b0fe3b0b2a07
STIX ID: report--01ecbe55-af10-56eb-ab6c-b0fe3b0b2a07
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-07-03
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
UNC5174 ("Houken") exploited Ivanti CSA zero-days to execute a base64-encoded Python payload that harvested admin credentials from a local PostgreSQL database, deployed or modified PHP webshells, and in some cases installed a custom Linux rootkit (sysinitd.ko) enabling TCP hijacking and remote root access; the actor performed lateral movement (e.g., to F5 BIG-IP), credential harvesting, reverse-shell persistence (GOREVERSE) and proxying (Neo-reGeorg, suo5), reused anonymized VPN/VPS infrastructure, and exfiltrated email data from at least one Ministry of Foreign Affairs mailbox while also conducting Monero cryptomining.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
