Houken is a Chinese state-sponsored threat actor targeting critical infrastructure networks, particularly in France.
Analyst brief
Houken is a Chinese state-sponsored threat actor targeting critical infrastructure networks, with a particular focus on entities in France. The group gains initial access by exploiting zero-day vulnerabilities in Ivanti Cloud Services Appliance devices. Houken maintains persistence using a sophisticated rootkit and open-source tools, primarily authored by Chinese-speaking developers. Defenders must prioritize immediate patching of Ivanti CSA vulnerabilities, deploy continuous monitoring to detect anomalous rootkit behavior and lateral movement, and enforce strict network segmentation to limit the impact of potential footholds sold as initial access.
Houken
unknown
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to critical infrastructure networks, particularly in France. The group employs a sophisticated rootkit alongside open-source tools, primarily developed by Chinese-speaking authors, to maintain persistence and control over compromised systems. Houken is suspected to operate as an initial access broker, selling footholds in targeted networks to other threat actors for further exploitation.