BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Exploit Ivanti CSA Zero-Days in Major France Attack

Chinese Threat Actors Exploit Ivanti Zero-Days to Target French Critical Sectors in 2024

  • Chinese threat group exploited zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices to target French critical sectors.
  • The campaign affected government, telecom, media, finance, and transport organizations starting in September 2024.
  • Attackers used advanced methods like rootkits, commercial VPNs, and open-source tools for persistent network access.
  • Exploited vulnerabilities include CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190.
  • The campaign appears to involve multiple threat actors, with some seeking financial gain and others providing access to state-linked groups.

French authorities reported that a Chinese-based Hacking group launched an attack campaign against major sectors in France, including government, telecommunications, media, finance, and transport. The campaign began in September 2024 and focused on exploiting several unpatched security flaws—known as zero-days—in Ivanti Cloud Services Appliance (CSA) devices.

- Advertisement -

The French National Agency for the Security of Information Systems (ANSSI) stated that the group, identified as Houken, shares connections with the threat cluster UNC5174, also called Uteus or Uetus, tracked by Google Mandiant. According to ANSSI, the attackers combined the use of unknown software vulnerabilities, a concealed rootkit (a tool that hides the attacker’s presence), and a range of open-source programs mainly developed by Chinese-speaking programmers.

ANSSI reported, “Houken’s attack infrastructure is made up of diverse elements—including commercial VPNs and dedicated servers.” HarfangLab, a French Cybersecurity firm, described a multi-party approach: one party finds software vulnerabilities, a second group uses them for network access, and third parties carry out follow-on attacks. According to ANSSI, “The operators behind the UNC5174 and Houken intrusion sets are likely primarily looking for valuable initial accesses to sell to a state-linked actor seeking insightful intelligence.”

The attackers targeted three specific Ivanti CSA vulnerabilities—CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190. They used different methods to steal credentials and maintain system access, such as installing PHP web shells, modifying existing scripts, or deploying a kernel module rootkit. Tools like the Behinder and NEO-reGeorg web shells, the GOREVERSE backdoor, and the suo5 proxy were observed in use.

The attacks also involved a Linux kernel module called “sysinitd.ko,” which lets attackers hijack all inbound traffic and execute commands with full administrative privileges. Some attackers reportedly patched the same vulnerabilities after exploiting them, likely to stop other groups from using the same systems.

- Advertisement -

The broader campaign affected organizations throughout Southeast Asia and Western governments, education sectors, NGOs, and media outlets. In some cases, the attackers used access for cryptocurrency mining. French authorities suggested the actors might be a private group selling access and information to various state-linked organizations while conducting their own profit-driven operations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fake Death of Oldest Tortoise Used in Crypto Scam

Crypto scammers falsely reported the death of Jonathan, a 194-year-old tortoise, in a bid...

Coinbase receives OCC approval for national trust charter.

Coinbase has received conditional approval from the US OCC for a national bank trust...

Fake Installers Spread Cryptojacking Malware, RATs

A financially motivated group, REF1695, uses fake software installers to deploy cryptocurrency miners and...

Trump Crypto Project Rated Among Industry’s Riskiest

The newly launched ratings firm CORE3 has assigned a 'DDD' risk grade to the...

U.S. Crypto Clarity Act Nears Key Senate Deal

Coinbase Chief Legal Officer Paul Grewal announced lawmakers are nearing a resolution on disputed...

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading