Houken is a China-linked intrusion set overlapping with UNC5174 (also known as Uteus) that has conducted campaigns since at least September 2024. It targeted French government, telecom, media, finance, and transport organizations, and also prioritized Southeast Asian governments, education, NGOs, and Western state-linked institutions. ANSSI reported the group exploited Ivanti Cloud Service Appliance (CSA) zero-day vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 to gain initial access. After compromise, operators used a base64-encoded Python script to extract credentials from a local PostgreSQL database, established persistence through PHP webshells, modified PHP scripts and php.ini, and deployed a custom Linux rootkit, sysinitd.ko, for TCP hijacking and remote root access. Observed tooling included Neo-reGeorg, Behinder, GOREVERSE, suo5, and VShell. Houken activity also included reconnaissance, credential theft, lateral movement including to F5 BIG-IP devices, data exfiltration, and in some cases Monero cryptomining via C3Pool infrastructure. In at least one confirmed case, the group exfiltrated email data from a Ministry of Foreign Affairs mailbox server in South America. The operators used anonymized infrastructure including Tor, NordVPN, ExpressVPN, Proton VPN, VPS providers, and residential IPs, and were observed reusing IP addresses and self-patching exploited systems to block rival actors. The activity has been assessed as aligned with China Standard Time and linked to China’s Ministry of State Security through overlap with UNC5174.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Houken is a tool used for exfiltrating email data from compromised servers.
Houken is a China-linked intrusion set that leverages zero-day vulnerabilities, rootkits, and open-source tools to gain and maintain access to high-value targets. It acts as an access broker, selling footholds, and is involved in credential theft, data exfiltration, and cryptomining. The group uses advanced techniques such as chaining zero-days, deploying webshells, and installing rootkits for persistence and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.