Chinese Hacking Group Targets French Entities Using Ivanti CSA Vulnerabilities
Overview of the Cyber Attack
The threat landscape continues to evolve as a recent cyber attack has come to light, orchestrated by a Chinese hacking group targeting a range of entities in France, including governmental and private sectors. This malicious campaign exploits several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The French cybersecurity agency, ANSSI, disclosed these findings on July 3, 2025, revealing the scale and implications of the attack.
The Houken Intrusion Set
Identified as part of a coordinated effort, this campaign is attributed to a group known as Houken. It has been noted that there are significant overlaps with another threat cluster monitored by Google Mandiant, referred to as UNC5174. This duality in naming suggests that Houken is not only a standalone entity but may also lend its techniques and tools to other malicious actors in the cyber realm.
Tactics, Techniques, and Targeting
According to ANSSI, the Houken group employs an array of sophisticated strategies. They capitalize on zero-day vulnerabilities, utilizing advanced rootkits and an arsenal of open-source tools developed by Chinese-speaking engineers. Their infrastructure integrating commercial VPNs and dedicated servers makes it particularly difficult to trace their activities.
The group’s operational model appears multi-faceted, as it seems to function as an initial access broker. This involves identifying vulnerabilities, leveraging them to create points of entry into target networks, and then distributing access to other threat actors for further exploitation. This organized approach highlights a collaborative element to cybercrime that poses significant risks to various sectors.
Previous Exploits and Known Vulnerabilities
ANSSI’s analysis draws attention to other exploits linked to the UNC5174 group, including the active exploitation of SAP NetWeaver vulnerabilities, leading to attacks with GOREVERSE malware. Similar tactics have been leveraged against vulnerabilities in other prevalent software, such as those from Palo Alto Networks and F5, raising alarms about potential vulnerabilities across numerous platforms.
In documenting their method of infiltration, ANSSI expressed concern over three specific security flaws in Ivanti CSA devices—CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190. These vulnerabilities were exploited in different ways, including:
- Direct deployment of PHP web shells.
- Modification of existing scripts to embed web shell functionalities.
- Installation of a kernel module functioning as a rootkit.
Methodologies and Tools Used
The attackers’ operation involves both well-known web shells like Behinder and neo-reGeorg and the ongoing deployment of GOREVERSE for maintaining persistence. In addition, they utilize a tunneling tool dubbed suo5 alongside a kernel module referred to as sysinitd.ko. This Linux kernel component is particularly notable for its capability to hijack TCP traffic, thereby allowing command executions with root privileges.
ANSSI’s report indicates that these actors are not just passively lurking; they are actively attempting to patch vulnerabilities. This unusual behavior suggests a desire to limit exploitation from other threat actors, indicating a strategic approach to controlling the narrative within the cyber ecosystem.
Broad Targeting Scope
The scope of Houken’s operations suggests a wide-ranging targeting strategy. The actors are believed to direct their focus towards various sectors, including government and education in Southeast Asia, along with non-governmental organizations based in China and surrounding regions. Notably, they also have shown interest in governmental and media sectors within Western countries, illustrating the global ambition of their cyber operations.
Financial Motivations
In an intriguing dimension of their operations, there have been reports of Houken leveraging their access to deploy cryptocurrency miners, raising questions about financial motivations behind their cyber activities. This aspect points toward a potential business model where access points are not just sold for intelligence gathering but also exploited for direct financial gain.
Key Takeaways
The ongoing exploits of the Houken group underscore the increasing sophistication and collaborative nature of cyber threats. By sharing access points and strategies across various threat actors, they create a complex web of vulnerabilities that makes cybersecurity increasingly challenging. The international scope and financial motivations of these attacks serve as a stark reminder of the pressing need for robust cybersecurity measures across all sectors.


