logo

Houken seeking a path by living on the edge with zero-days

ID: dc47ddcd-50e3-4ba3-9b36-267a9ddb2e03

STIX ID: report--dc47ddcd-50e3-4ba3-9b36-267a9ddb2e03

Threat Score

85/100

Uploaded: 2026-07-29

Published Date: 2026-07-29

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI describes the Houken intrusion set that opportunistically exploited multiple Ivanti CSA zero-days in Sept 2024 to obtain initial access across government, telecom, media, finance and transport sectors, deploying PHP webshells, public offensive tools and a novel kernel rootkit, documenting IoCs and linking the activity to UNC5174 and potential access-brokering for state-aligned intelligence collection.