Full Report
The French cybersecurity agency identified Houken, a new Chinese intrusion campaign targeting various industries in France
Analysis Summary
# Threat Actor: Houken Intrusion Set / UNC5174
## Attribution & Identity
Operated by a threat actor believed to be linked to China’s Ministry of State Security (MSS).
This actor is also associated with the intrusion set previously described by Google Threat Intelligence Group (GTIG) as **UNC5174**.
The actors leverage open-source tools of likely Chinese origin.
## Activity Summary
Detected in September 2024, with potential activity dating back to 2023. The campaign, dubbed **Houken**, targets French organizations across various sectors. The primary goal appears to be gaining initial access into networks, which are then sold to a state-linked actor seeking intelligence. The campaign heavily leverages zero-day exploits against Ivanti products.
## Tactics, Techniques & Procedures
- Exploitation of zero-day vulnerabilities (specifically CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti products).
- Use of a sophisticated rootkit.
- Reliance on open-source tools of likely Chinese origin.
- Use of commercial VPN solutions for obfuscation.
- Establishment of dedicated Command-and-Control (C2) infrastructure.
## Targeting
- Sectors: Various sectors in France (unspecified industries).
- Geography: France.
- Victims: French organizations targeted for initial network penetration.
## Tools & Infrastructure
- **Malware families used:** A sophisticated rootkit was deployed.
- **Infrastructure (C2, domains, IPs):** Commercial Virtual Private Network (VPN) solutions and dedicated Command-and-Control (C2) servers.
## Implications
This operation suggests ongoing, state-sponsored espionage activity targeting critical infrastructure or sensitive entities in France. The reliance on zero-days indicates a high level of sophistication and resourcefulness. Furthermore, the actor appears to operate as an Initial Access Broker (IAB) function, selling access to other state-linked actors seeking intelligence, highlighting a tiered espionage model.
## Mitigations
- Immediately patch or apply mitigations for Ivanti products, focusing on CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
- Monitor command and control traffic originating from commercial VPN services that might be co-opted for malicious persistence.
- Implement rigorous detection for sophisticated rootkit behaviors indicative of persistent access.