logo

Initial Access Broker Self-Patches Zero Days as Turf Control

ID: fc3523c8-df32-55d6-ba1a-377523374f30

STIX ID: report--fc3523c8-df32-55d6-ba1a-377523374f30

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-07-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

ANSSI observed a campaign by an intrusion set called "Houken" (likely the initial access broker UNC5174) exploiting three Ivanti Connect Secure zero-day vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to gain access to organizations across France and Southeast Asia; the operators harvested credentials, established persistence (including rootkits), sometimes performed lateral movement, and then self-patched the exploited flaws to lock out other threat actors, indicating both operational sophistication and motives to sell access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.