Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Houken

Also known as: Synaptics worm, Hou Ken, Scattered Spider

Description

Houken, first identified by France’s National Cybersecurity Agency (ANSSI) in September 2024, uses a combination of state‑grade zero‑day exploits targeting the Ivanti Cloud Service Appliance (CSA) in governmental, telecommunications, media, finance and transport organizations. Once compromised, the actor installs a custom rootkit that persists across reboots, enabling long‑term control while remaining stealthy through obfuscation and native system services. Operationally, Houken relies on a diversified attack infrastructure comprising commercial VPN providers, dedicated servers and a portfolio of open‑source tools developed by Chinese-speaking authors. The group appears to be linked with the UNC5174 intrusions described by MANDIANT, suggesting shared capabilities and possibly common personnel or funding streams. Houken is believed to monetize its activity in two distinct ways: firstly, by acting as an access broker selling initial footholds to other state‑linked actors for deeper espionage; secondly, by conducting straightforward profit‑driven operations such as data exfiltration and crypto‑mining. Although the primary motive is espionage, the actor’s recent campaigns indicate a pragmatic focus on revenue generation. Future analysis will need to confirm whether Houken maintains persistence beyond initial access and how actively it sells compromised environments to other actors in its ecosystem.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Media
Financial services
Critical infrastructure
Defense
Non profit
Healthcare
Aerospace
Aviation
Manufacturing
Education
Think tank
Nuclear
Energy
Transportation
Retail

Targeted Countries / Regions

CN
RU
US
FR
TW
GB
IN
IR
IL
SA
UA
PK

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Houken is a Chinese state‑linked intrusion set that exploited multiple zero‑day flaws in Ivanti Cloud Service Appliance devices to gain initial access into French critical infrastructure networks. The actor deploys a sophisticated rootkit and leverages a mix of commercial VPNs, dedicated servers and open‑source tools primarily authored by Chinese developers. Houken is believed to operate as an initial‑access broker, offering footholds to other threat actors while also engaging in data exfiltration and cryptomining for profit.

Goals & Targeting

Houken appears driven by dual objectives: state‑level intelligence gathering across sectors that hold strategic or financial value, and the monetization of compromised environments. By targeting French governmental agencies and critical infrastructure operators, the actor seeks valuable data while simultaneously providing footholds for broader espionage networks. The broad sector coverage—including telecommunications, media, finance, transport and energy—suggests a focus on information that can influence policy, secure economic assets or support geopolitical objectives. Geographically, Houken’s known samples and reported exploits center on France but the actor’s listed target countries (China, Russia, United States, France, Taiwan, Great Britain, India, Iran, Israel, Saudi Arabia, Ukraine, Pakistan) indicate a willingness to operate across multiple theaters. The combination of espionage and profit motives aligns with a model where initial access is sold to other actors who may pursue deeper operational goals, such as sabotage or insider threat facilitation. Typical victims are large, highly connected entities that manage sensitive data or infrastructure controls—making them attractive for both intelligence purposes and the installation of cryptomining payloads to exploit their computational resources.

Enhanced Description

Key Capabilities

  • Exploitation of zero‑day vulnerabilities in IoT/edge devices
  • Deployment of a sophisticated rootkit for persistence and stealth
  • Use of commercial VPN services and dedicated servers as command & control infrastructure
  • Leveraging open‑source tools developed by Chinese-speaking authors
  • Acting as an initial‑access broker that sells compromised footholds
  • Conducting data exfiltration via established C2 channels
  • Deploying cryptomining payloads to monetize compromised systems
  • Utilizing PowerShell scripts for post‑exploitation activity

MITRE ATT&CK Tactics

Initial Access
Privilege Escalation
Persistence
Defense Evasion
Exfiltration

ATT&CK Techniques

T1203 Exploit Public-Facing Application
T1059.001 PowerShell
T1060 Create or Modify System Process (rootkit)
T1041 Exfiltration Over Command and Control Channel
T1491.001 System Resource Hijacking: Cryptomining

Software / Tooling

Matryoshka
Invisible Ferret
BeaverTail
Akira
Milan
XORIndex Loader
Ghost RAT
ValleyRAT
RedLine
PowerShell scripts
Scheduled Task manipulation

Campaigns & Victims

Houken first surfaced in September 2024 when ANSSI identified a campaign exploiting three zero‑day flaws on Ivanti Cloud Service Appliance devices that affected French government, telecommunications and transport organizations. The attack used an uncommon intrusion set, later named Houken, which relied on both state‑grade zero‐days and a suite of open‑source tools for post‑exploitation. Operational tempo appeared moderate, with multiple exploitation attempts over several weeks; the actor’s infrastructure comprised commercial VPNs and dedicated servers that masked traffic. The group also displayed elements typical of an access broker: one documented case of data exfiltration coupled with an evident interest in deploying cryptomining operations for direct profit. The linkage to UNC5174 suggests a broader network of intrusions aimed at acquiring initial footholds for resale or future exploitation. Although limited public information exists beyond the French incident, available intelligence implies that Houken is focused on critical sectors and will likely expand attacks globally if more zero‑days become available.

IOC Patterns

  • Domain names mimicking legitimate government or ISP names; e.g., .fr domains used for C2 infrastructure
  • Use of commercial VPN services and cloud hosting providers as staging points
  • Email addresses linked to European certification authorities (e.g., cert.europa.eu) for credential theft or phishing
  • Exploitation of specific Ivanti CSA devices via CVE‑level zero‑days

Recommended Actions

  • Deploy timely patches or mitigations for all known Ivanti Cloud Service Appliance vulnerabilities; monitor for failed authentication attempts and exploit indicators.
  • Implement endpoint detection and response (EDR) solutions that detect rootkit behavior, malicious DLL loading, and PowerShell obfuscation.
  • Block outbound connections to known commercial VPN and dedicated server IP ranges used by Houken, while monitoring legitimate traffic to detect anomalous usage patterns.
  • Enforce least‑privilege policies on all systems exposed to the internet; remove unnecessary administrative access and harden default credentials.
  • Conduct active threat hunting for signs of data exfiltration over standard C2 channels (HTTP/S) and crypto‑mining activity, using indicators such as high CPU utilisation and unfamiliar binary processes.
  • Establish a formal incident response plan that includes steps to isolate compromised devices quickly and preserve forensic evidence related to rootkits and backdoors.

Suggested Tags

APT
state-sponsored
espionage
critical infrastructure
government
financial services
telecommunications
media
transportation
data exfiltration
cryptomining

Confidence Assessment

Confidence in the core facts—Houken’s exploitation of zero‑day vulnerabilities on Ivanti CSA devices, rootkit deployment and use of commercial VPNs—is high, based on ANSSI reports from September 2024 and corroborating Malpedia documentation. The association with UNC5174 and the suspected access‑broker role are moderate confidence due to limited independent confirmation beyond MANDIANT’s description; further evidence would strengthen understanding of operational scope. Gaps remain regarding the full spectrum of targeted countries outside France, the range of tools employed beyond those listed, and the extent of post‑exploitation activity such as data exfiltration or crypto mining in other sectors.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cert.europa.eu — Cited by web research for: Turla
  2. www.cert.ssi.gouv.fr — Cited by web research for: Leverage
  3. https://malpedia.caad.fkie.fraunhofer.de/actor/houken — Cited by AI analysis.
  4. https://threats.wiz.io/all-techniques — Cited by AI analysis.
  5. https://www.cert.ssi.gouv.fr — Cited by AI analysis.

Intel Summary

5

Techniques

42

Tools

0

Campaigns

10

IOCs

0

Observed Data

1

Tactics

Tags

APT
Critical Infrastructure
Zero-Day Exploitation
China-state-sponsored
initial-access-broker
critical-infrastructure-targeting
Ivanti-exploitation
state-sponsored
espionage
critical infrastructure
government
financial services
telecommunications
media
transportation
data exfiltration
cryptomining

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.