Also known as: Synaptics worm, Hou Ken, Scattered Spider
Houken, first identified by France’s National Cybersecurity Agency (ANSSI) in September 2024, uses a combination of state‑grade zero‑day exploits targeting the Ivanti Cloud Service Appliance (CSA) in governmental, telecommunications, media, finance and transport organizations. Once compromised, the actor installs a custom rootkit that persists across reboots, enabling long‑term control while remaining stealthy through obfuscation and native system services. Operationally, Houken relies on a diversified attack infrastructure comprising commercial VPN providers, dedicated servers and a portfolio of open‑source tools developed by Chinese-speaking authors. The group appears to be linked with the UNC5174 intrusions described by MANDIANT, suggesting shared capabilities and possibly common personnel or funding streams. Houken is believed to monetize its activity in two distinct ways: firstly, by acting as an access broker selling initial footholds to other state‑linked actors for deeper espionage; secondly, by conducting straightforward profit‑driven operations such as data exfiltration and crypto‑mining. Although the primary motive is espionage, the actor’s recent campaigns indicate a pragmatic focus on revenue generation. Future analysis will need to confirm whether Houken maintains persistence beyond initial access and how actively it sells compromised environments to other actors in its ecosystem.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Houken is a Chinese state‑linked intrusion set that exploited multiple zero‑day flaws in Ivanti Cloud Service Appliance devices to gain initial access into French critical infrastructure networks. The actor deploys a sophisticated rootkit and leverages a mix of commercial VPNs, dedicated servers and open‑source tools primarily authored by Chinese developers. Houken is believed to operate as an initial‑access broker, offering footholds to other threat actors while also engaging in data exfiltration and cryptomining for profit.
Goals & Targeting
Houken appears driven by dual objectives: state‑level intelligence gathering across sectors that hold strategic or financial value, and the monetization of compromised environments. By targeting French governmental agencies and critical infrastructure operators, the actor seeks valuable data while simultaneously providing footholds for broader espionage networks. The broad sector coverage—including telecommunications, media, finance, transport and energy—suggests a focus on information that can influence policy, secure economic assets or support geopolitical objectives. Geographically, Houken’s known samples and reported exploits center on France but the actor’s listed target countries (China, Russia, United States, France, Taiwan, Great Britain, India, Iran, Israel, Saudi Arabia, Ukraine, Pakistan) indicate a willingness to operate across multiple theaters. The combination of espionage and profit motives aligns with a model where initial access is sold to other actors who may pursue deeper operational goals, such as sabotage or insider threat facilitation. Typical victims are large, highly connected entities that manage sensitive data or infrastructure controls—making them attractive for both intelligence purposes and the installation of cryptomining payloads to exploit their computational resources.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Houken first surfaced in September 2024 when ANSSI identified a campaign exploiting three zero‑day flaws on Ivanti Cloud Service Appliance devices that affected French government, telecommunications and transport organizations. The attack used an uncommon intrusion set, later named Houken, which relied on both state‑grade zero‐days and a suite of open‑source tools for post‑exploitation. Operational tempo appeared moderate, with multiple exploitation attempts over several weeks; the actor’s infrastructure comprised commercial VPNs and dedicated servers that masked traffic. The group also displayed elements typical of an access broker: one documented case of data exfiltration coupled with an evident interest in deploying cryptomining operations for direct profit. The linkage to UNC5174 suggests a broader network of intrusions aimed at acquiring initial footholds for resale or future exploitation. Although limited public information exists beyond the French incident, available intelligence implies that Houken is focused on critical sectors and will likely expand attacks globally if more zero‑days become available.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core facts—Houken’s exploitation of zero‑day vulnerabilities on Ivanti CSA devices, rootkit deployment and use of commercial VPNs—is high, based on ANSSI reports from September 2024 and corroborating Malpedia documentation. The association with UNC5174 and the suspected access‑broker role are moderate confidence due to limited independent confirmation beyond MANDIANT’s description; further evidence would strengthen understanding of operational scope. Gaps remain regarding the full spectrum of targeted countries outside France, the range of tools employed beyond those listed, and the extent of post‑exploitation activity such as data exfiltration or crypto mining in other sectors.
No campaigns linked yet.
No observed data linked yet.
5
Techniques
42
Tools
0
Campaigns
10
IOCs
0
Observed Data
1
Tactics