China-linked group Houken hit French organizations using zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-8963 | Unauthenticated Path Traversal in Ivanti Cloud Services Appliance CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets. Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions. | 9.1 | 99% | KEV |
| moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted) | |
| CVE-2024-9380 | OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile). Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise. | 7.2 | 63% | KEV |
| moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands |
Full article548 words · extracted from securityaffairs.com · click to collapse

China-linked group Houken hit French govt, telecom, media, finance and transport sectors using Ivanti CSA zero-days, says France’s ANSSI.
France’s cyber agency ANSSI revealed that a Chinese hacking group used Ivanti CSA zero-days to target government, telecom, media, finance, and transport sectors. The campaign, active since September 2024, is linked to the Houken intrusion set, which overlaps with UNC5174 (aka Uteus), tracked by Mandiant.
In September 2024, ANSSI identified a campaign exploiting Ivanti CSA zero-days to breach French entities across key sectors. The attack used a unique intrusion set, dubbed Houken, which combines zero-day exploits and a rootkit with Chinese open-source tools and diverse infrastructure like VPNs and dedicated servers. Houken likely serves as an access broker selling system footholds, with some activity showing data theft and cryptomining.
“At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-20248190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices. These vulnerabilities were exploited as zero-days, before the publication of the Ivanti security advisory.” reads the report published by ANSSI. “The attacker opportunistically chained these vulnerabilities to gain initial access on Ivanti CSA appliances, with the intention of:
- Obtaining credentials through the execution of a base64 encoded Python script1.
- Ensuring persistence, by:– deploying or creating PHP webshells;– modifying existing PHP scripts to add webshells capabilities;– occasionally installing a kernel module which acts as a rootkit once loaded.
The attacker tried to self-patch Ivanti CSA flaws to block other threat actors, then moved laterally, did reconnaissance activities, stole credentials, and set persistence. ANSSI saw activity in November 2024.
At the end of 2024, the French cyber agency observed multiple attacks on local entities across key sectors. After compromising Ivanti CSA devices, attackers moved laterally, stole credentials, and tried to persist on networks. The government experts pointed out that the activity aligned with China Standard Time (UTC+8). ANSSI aided impacted organizations with forensics and response.
The Houken intrusion set exploited zero-day flaws in Ivanti CSA devices to gain initial access to French networks. Once inside, attackers used tools like Neo-reGeorg, Behinder, and GOREVERSE to maintain persistence and control the compromised systesm. Their infrastructure included anonymization services (e.g., NordVPN, Tor), VPSs, and residential IPs. They reused IPs, deployed webshells, modified PHP scripts, and used a sophisticated rootkit to hijack TCP traffic. The TTPs suggest a capable actor targeting high-value systems, likely for espionage or sale of access.
The Houken’s tactics range from basic, noisy use of open-source tools, often developed by Chinese-speaking communities, to more advanced techniques like zero-day exploitation and rootkit development, hinting at a multi-actor operation. Houken targets a wide array of entities, prioritizing Southeast Asian governments and education sectors, NGOs, and Western institutions linked to state functions. Links to UNC5174, a group tied to China’s MSS, suggest a shared operator selling access and intelligence.
“the threat actor behind the Houken and UNC5174 intrusion sets might correspond to a private entity, selling accesses and worthwhile data to several state-linked bodies while seeking its own interests leading lucrative oriented operations. Such behaviour was already observed for Chinese-linked intrusion sets related to the APT41 galaxy and previously linked to numerous private sector entities [13].” ANSSI concludes.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, China-linked group Houken)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179602/apt/china-linked-group-houken-hit-french-organizations-using-zero-days.html