ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault1

Chinese Hackers Target France in Ivanti Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
CVE-2024-8963
Unauthenticated Path Traversal in Ivanti Cloud Services Appliance

CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets.

Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions.

9.199% KEV
  • Ivanti Cloud Services Appliance (CSA) CSA 4.6.x before 4.6 Patch 519
moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted)
CVE-2024-9380
OS Command Injection RCE in Ivanti Cloud Services Appliance Admin Console

CVE-2024-9380 is an OS command injection flaw (CWE-77/CWE-78) in the admin web console of Ivanti Cloud Services Appliance (CSA), fixed in version 5.0.2. A remote attacker who is already authenticated with administrative privileges can inject arbitrary operating system commands through the console, which the appliance then executes. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). All CSA releases before 5.0.2 are affected, and the widely deployed 4.6.x line has reached End-of-Life, so EOL users must remove it from service or move to 5.0.x or later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-09, and contemporaneous reporting describes Chinese nation-state actors exploiting Ivanti CSA zero-days against French government and telecom targets, with a 63.2% EPSS probability of exploitation in the next 30 days (99th percentile).

Do: Upgrade Ivanti CSA to 5.0.2 or later; if you are running the End-of-Life 4.6.x line, either remove it from service or migrate to the supported 5.0.x line, per CISA's KEV required action. Restrict exposure of the admin web console (do not leave it directly internet-facing) and verify whether your appliance was targeted. Given reported nation-state exploitation of CSA zero-days, review appliance logs and admin credentials for signs of compromise.

7.263% KEV
  • Ivanti Endpoint Manager Cloud Services Appliance (CSA) all versions before 5.0.2, including the End-of-Life 4.6.x line
moderate≈ a few thousand internet-exposed CSA appliances; total installed base likely in the low tens of thousands
Full article680 words · extracted from infosecurity-magazine.com · click to collapse

France’s national cybersecurity agency, ANSSI, has identified a new cyber intrusion campaign targeting French organizations in various sectors.

The campaign was detected in September 2024, but it could have dated back to 2023. Dubbed Houken, the intrusion set is moderately sophisticated and involves zero-day exploits, open-source tools of likely Chinese origin, a sophisticated rootkit and an attack infrastructure comprising commercial virtual private network (VPN) solutions and dedicated command-and-control (C2) servers.

In a report published by ANSSI’s Computer emergency response team (CERT-FR) on July 1, 2025, the agency assessed that the Houken intrusion set is operated by the same threat actor as the intrusion set previously described by Google Threat Intelligence Group (GTIG) as UNC5174, which is believed to be an initial access broker for the China’s Ministry of State Security (MSS).

In this newly identified campaign, ANSSI estimated that the threat actor likely uses Houken to gain initial access into a network in order to sell it to a state-linked actor seeking intelligence.

Read more: Chinese State Hackers Exploiting Newly Disclosed Ivanti Flaw

ANSSI’s Assessment of the Ivanti Exploits

At the beginning of September 2024, an attacker repeatedly exploited CVE-2024-8190, CVE-2024-8963 and CVE-2024-9380, three high to critical zero-day vulnerabilities affecting Ivanti Cloud Service Appliance (CSA), to remotely execute arbitrary code on vulnerable devices.

The actor chained the three exploits to obtain credentials through the execution of a base64 encoded Python script and ensured persistence by deploying or creating PHP webshells, modifying existing PHP scripts to add webshells capabilities and occasionally installing a kernel module which acts as a rootkit once loaded.

These vulnerabilities were patched on September 10, September 15 and October 8, respectively.

Additionally, the attacker attempted to self-patch web resources affected by the vulnerabilities, likely to prevent exploitation by additional unrelated actors, according to ANSSI.

“On occasions, and after establishing a foothold on victim networks through the compromise of Ivanti CSA devices, the attacker performed reconnaissance activities and moved laterally,” ANSSI said.

In three cases, the compromise of Ivanti CSA devices was followed by lateral movements toward the victims’ internal information systems.

These attacks lasted at least until November 2024 and affected French organizations in governmental, telecommunications, media, finance and transport sectors.

“ANSSI provided significant support to these entities, assisting in the conduct of forensic analysis and corrective actions regarding these incidents,” said the report.

The attacker’s operational activities time zone was UTC+8, which aligns with China Standard Time (CST).

The Houken Intrusion Set in Focus

The attack infrastructure of the Houken intrusion set was composed of diverse elements, including IP addresses from:

  • Popular and publicly accessible anonymisation services, such as ExpressVPN, NordVPN, Proton VPN and Surfshark
  • Dedicated servers, mainly virtual private servers (VPS) hosted by HOSTHATCH, ColoCrossing and JVPS.hosting
  • Internet service providers (ISPs), such as Comcast, China Unicom, China Telecom and Airtel

Additionally, the Houken toolset in the campaigns starting in September 2024 included:

  • Many open-source tools available on GitHub, including webshells, mostly crafted by Chinese-speaking developers (e.g. Neo-reGeorg)
  • Handcrafted webshells
  • A Linux kernel module and a user-space binary acting as a rootkit

According to CERT-FR researchers, the threat actor displayed a mix of unsophisticated and advanced tactics.

While some of their actions, such as noisy operations and the use of generic offensive tools, suggested limited resources for tool development, the exploitation of zero-day vulnerabilities and the deployment of rootkits indicated access to significant technical capabilities.

This divergence in terms of skills and resources, as well as the use of multiple commercial VPN exit nodes or the diversity of dedicated servers, may reflect a multi-actor approach, as described by HarfangLab’s Cyber Threat Research Team in a February 2025 report on the same Ivanti vulnerabilities exploitation campaign.

Aside from its targets in France, the ANSSI report noted that the threat actor behind Houken has an extensive targeting range, with the following priorities:

  • Entities located near China, especially in Southeast Asia (e.g., Thailand, Vietnam, Indonesia) and with a specific focus on governmental and education sectors
  • NGOs inside and outside China, including Hong Kong and Macao
  • Entities based in Western countries associated with governmental, defence, education, media or telecommunication sectors

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinese-hackers-france-ivanti/