logo

Ivanti Zero-Day Exploited by Chinese Hackers

ID: ed9425e3-2078-568e-a719-d2ffa9f15ee4

STIX ID: report--ed9425e3-2078-568e-a719-d2ffa9f15ee4

Feed Name: Canary Trap

Threat Score
92/100

Date Published: 2025-07-14

Date Updated: 2026-05-13

Author: Canary Trap

...
...

Chinese state-linked actors (Houken / UNC5174) exploited three Ivanti CSA zero-days (CVE-2024-8963, CVE-2024-9380, CVE-2024-8190) beginning September 2024 to compromise French government, telecom, finance and media organizations and others worldwide, deploying PHP web shells, open-source tunneling tools and a custom Linux kernel rootkit (sysinitd.ko) to gain root execution, persistence and stealth; operators also patched the exploited flaws to deny rivals, conducted initial access brokering, and carried out opportunistic cryptojacking while primarily pursuing intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.