Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms

The French cybersecurity agency said Tuesday that a malicious campaign by a Chinese hacker group that weaponized multiple zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices affected several organizations in the country’s governmental, telecommunications, media, finance, and transportation sectors.

The campaign was discovered in early September 2024 and has been linked to a unique intrusion set nicknamed Houken. It is estimated that this intrusion set shares certain level overlaps with a threat cluster that Google Mandiant tracks under the designation UNC5174 (also known as Uteus or Uetus).

According to the French National Agency for the Security of Information Systems (ANSSI), its operators use a variety of open-source tools, most of which were created by Chinese-speaking developers, in addition to zero-day vulnerabilities and an advanced rootkit. Commercial VPNs and dedicated servers are just two of the many components read more about Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government Telecoms.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *