Initial Access Broker Self-Patches Zero Days as Turf Control
ID: fc3523c8-df32-55d6-ba1a-377523374f30
STIX ID: report--fc3523c8-df32-55d6-ba1a-377523374f30
Feed Name: Dark Reading
ANSSI observed a campaign by an intrusion set called "Houken" (likely the initial access broker UNC5174) exploiting three Ivanti Connect Secure zero-day vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to gain access to organizations across France and Southeast Asia; the operators harvested credentials, established persistence (including rootkits), sometimes performed lateral movement, and then self-patched the exploited flaws to lock out other threat actors, indicating both operational sophistication and motives to sell access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
