Houken seeking a path by living on the edge with zero-days
ID: dc47ddcd-50e3-4ba3-9b36-267a9ddb2e03
STIX ID: report--dc47ddcd-50e3-4ba3-9b36-267a9ddb2e03
Threat Score
85/100
Uploaded: 2026-07-29
Published Date: 2026-07-29
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI describes the Houken intrusion set that opportunistically exploited multiple Ivanti CSA zero-days in Sept 2024 to obtain initial access across government, telecom, media, finance and transport sectors, deploying PHP webshells, public offensive tools and a novel kernel rootkit, documenting IoCs and linking the activity to UNC5174 and potential access-brokering for state-aligned intelligence collection.
