sysinitd.ko is a custom Linux rootkit/kernel module used in campaigns attributed to Houken and linked to the UNC5174 (Uteus/Uetus) cluster. It was deployed after exploitation of Ivanti Cloud Services Appliance (CSA) vulnerabilities, including CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190, to establish persistence on compromised devices. According to the provided reporting, the malware consists of a kernel module (sysinitd.ko) and a user-space executable (sysinitd) installed via an install.sh shell script. Its core capability is hijacking inbound TCP traffic across all ports and invoking shells, enabling remote execution of arbitrary commands with root privileges and effectively providing remote root access. The malware was observed alongside PHP web shells, GOREVERSE, neo-reGeorg, Behinder, and the suo5 HTTP proxy tunneling tool. It was used in intrusions affecting French governmental, telecommunications, media, finance, transport, education, and NGO sectors, with broader targeting also noted in Southeast Asia, China, Hong Kong, Macau, and other Western countries. Fortinet documented the rootkit in October 2024 and January 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deployed a custom Linux rootkit (sysinitd.ko) allowing TCP hijacking and remote root access.
1 distinct technique documented for this family, organized by ATT&CK tactic.
– occasionally installing a kernel module which acts as a rootkit once loaded... In one incident targeting an entity of the French defense sector, Houken operators deployed a previously unobserved rootkit... It is composed of a kernel module (sysinitd.ko) and a user-space executable file (sysinitd)... By hijacking inbound TCP traffic over all ports, and invoking shells, sysinitd.ko and sysinitd allow the remote execution of any command with root privileges.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
sysinitd.ko is a custom Linux kernel rootkit that enables TCP hijacking and remote root access for attackers.
sysinitd.ko is a Linux kernel module rootkit that hijacks inbound TCP traffic and enables remote command execution with root privileges, providing deep persistence and control over compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.