Ivanti Zero-Day Exploited by Chinese Hackers
ID: ed9425e3-2078-568e-a719-d2ffa9f15ee4
STIX ID: report--ed9425e3-2078-568e-a719-d2ffa9f15ee4
Feed Name: Canary Trap
Chinese state-linked actors (Houken / UNC5174) exploited three Ivanti CSA zero-days (CVE-2024-8963, CVE-2024-9380, CVE-2024-8190) beginning September 2024 to compromise French government, telecom, finance and media organizations and others worldwide, deploying PHP web shells, open-source tunneling tools and a custom Linux kernel rootkit (sysinitd.ko) to gain root execution, persistence and stealth; operators also patched the exploited flaws to deny rivals, conducted initial access brokering, and carried out opportunistic cryptojacking while primarily pursuing intelligence collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
