Chinese Hackers Target French Government and Telecoms Using Ivanti CSA Zero-Day Exploits

Published:

spot_img

Chinese Hacking Group Targets French Entities Using Ivanti CSA Vulnerabilities

Overview of the Cyber Attack

The threat landscape continues to evolve as a recent cyber attack has come to light, orchestrated by a Chinese hacking group targeting a range of entities in France, including governmental and private sectors. This malicious campaign exploits several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The French cybersecurity agency, ANSSI, disclosed these findings on July 3, 2025, revealing the scale and implications of the attack.

The Houken Intrusion Set

Identified as part of a coordinated effort, this campaign is attributed to a group known as Houken. It has been noted that there are significant overlaps with another threat cluster monitored by Google Mandiant, referred to as UNC5174. This duality in naming suggests that Houken is not only a standalone entity but may also lend its techniques and tools to other malicious actors in the cyber realm.

Tactics, Techniques, and Targeting

According to ANSSI, the Houken group employs an array of sophisticated strategies. They capitalize on zero-day vulnerabilities, utilizing advanced rootkits and an arsenal of open-source tools developed by Chinese-speaking engineers. Their infrastructure integrating commercial VPNs and dedicated servers makes it particularly difficult to trace their activities.

The group’s operational model appears multi-faceted, as it seems to function as an initial access broker. This involves identifying vulnerabilities, leveraging them to create points of entry into target networks, and then distributing access to other threat actors for further exploitation. This organized approach highlights a collaborative element to cybercrime that poses significant risks to various sectors.

Previous Exploits and Known Vulnerabilities

ANSSI’s analysis draws attention to other exploits linked to the UNC5174 group, including the active exploitation of SAP NetWeaver vulnerabilities, leading to attacks with GOREVERSE malware. Similar tactics have been leveraged against vulnerabilities in other prevalent software, such as those from Palo Alto Networks and F5, raising alarms about potential vulnerabilities across numerous platforms.

In documenting their method of infiltration, ANSSI expressed concern over three specific security flaws in Ivanti CSA devices—CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190. These vulnerabilities were exploited in different ways, including:

  • Direct deployment of PHP web shells.
  • Modification of existing scripts to embed web shell functionalities.
  • Installation of a kernel module functioning as a rootkit.

Methodologies and Tools Used

The attackers’ operation involves both well-known web shells like Behinder and neo-reGeorg and the ongoing deployment of GOREVERSE for maintaining persistence. In addition, they utilize a tunneling tool dubbed suo5 alongside a kernel module referred to as sysinitd.ko. This Linux kernel component is particularly notable for its capability to hijack TCP traffic, thereby allowing command executions with root privileges.

ANSSI’s report indicates that these actors are not just passively lurking; they are actively attempting to patch vulnerabilities. This unusual behavior suggests a desire to limit exploitation from other threat actors, indicating a strategic approach to controlling the narrative within the cyber ecosystem.

Broad Targeting Scope

The scope of Houken’s operations suggests a wide-ranging targeting strategy. The actors are believed to direct their focus towards various sectors, including government and education in Southeast Asia, along with non-governmental organizations based in China and surrounding regions. Notably, they also have shown interest in governmental and media sectors within Western countries, illustrating the global ambition of their cyber operations.

Financial Motivations

In an intriguing dimension of their operations, there have been reports of Houken leveraging their access to deploy cryptocurrency miners, raising questions about financial motivations behind their cyber activities. This aspect points toward a potential business model where access points are not just sold for intelligence gathering but also exploited for direct financial gain.

Key Takeaways

The ongoing exploits of the Houken group underscore the increasing sophistication and collaborative nature of cyber threats. By sharing access points and strategies across various threat actors, they create a complex web of vulnerabilities that makes cybersecurity increasingly challenging. The international scope and financial motivations of these attacks serve as a stark reminder of the pressing need for robust cybersecurity measures across all sectors.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...