ANSSI reported that a threat cluster it tracks as Houken exploited three Ivanti Cloud Service Appliance zero-days—CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380—to compromise French organizations in government, telecommunications, media, finance, and transport. The intrusions focused on stealing credentials and maintaining access through PHP webshells, modified legitimate PHP files, and in at least one case a Linux rootkit installed on an internet-facing Ivanti CSA device. ANSSI said the actor used a blend of commercial VPNs, VPS infrastructure, Tor exit nodes, and residential or mobile IP space, and assessed with moderate confidence that Houken overlaps with UNC5174, a China-nexus intrusion set linked to initial access brokerage.
Follow-on investigations showed that after the zero-day exploitation, the attackers relied heavily on commodity open-source tooling for persistence and lateral movement. Synacktiv observed use of the suo5 HTTP proxy webshell to tunnel traffic through exposed servers, the iox tunneling tool for port forwarding and persistence, and a modified atexec-pro.py script to execute code remotely through Windows Task Scheduler. The findings indicate that while the initial compromise depended on advanced Ivanti exploitation, later activity created practical detection opportunities through recognizable post-exploitation tradecraft, including webshell deployment, tunneling behavior, and suspicious PowerShell spawned by task-based remote execution.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
On May 12, 2025, Synacktiv published analysis of the open-source post-exploitation tools used in Ivanti CSA intrusions, including suo5, iox, and a modified atexec-pro.py. The publication also released YARA and Sigma detection rules for these tools.
ANSSI said the most recent activity related to the Houken Ivanti CSA campaign was observed at the end of November 2024. In some French cases, the compromises had progressed from the internet-facing appliance into internal information systems.
ANSSI observed one NordVPN IP address used in two separate incidents on September 14, 2024, indicating infrastructure reuse by the attacker. The campaign used mixed infrastructure including commercial VPNs, VPS servers, Tor exit nodes, and residential or mobile IP space.
Threat actors were reported to be chaining Ivanti Cloud Services Appliance vulnerabilities as early as September 9, 2024, before Ivanti had publicly released advisories or patches. ANSSI later said the vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 were exploited as zero-days.
During post-compromise activity in the Ivanti CSA intrusions, attackers used a modified Impacket-based script named atexec-pro.py to execute commands on an Active Directory domain controller from another internal host. Synacktiv highlighted this as part of the lateral movement toolset seen in the cases it investigated.
In incidents that began with exploitation of vulnerable Ivanti CSA appliances in September and October 2024, attackers moved to internet-facing Microsoft Exchange servers and deployed the suo5 HTTP proxy webshell at OutlookEN.aspx. They also deployed the iox tunneling tool on the Ivanti CSA appliance to maintain access after patches were applied.
Ivanti published multiple security advisories in September and October 2024 for security policy bypass and remote code execution vulnerabilities affecting Cloud Services Appliance. These advisories followed exploitation activity that had already begun.
In September 2024, ANSSI observed a campaign exploiting Ivanti CSA devices to gain initial access to French organizations in government, telecommunications, media, finance, and transport. ANSSI named the intrusion set behind the activity Houken.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.