Houken

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:22:17

Targeted industries: government-and-public-sector

Targeted regions: country_code:fr

Context

Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to critical infrastructure networks, particularly in France. The group employs a sophisticated rootkit alongside open-source tools, primarily developed by Chinese-speaking authors, to maintain persistence and control over compromised systems. Houken is suspected to operate as an initial access broker, selling footholds in targeted networks to other threat actors for further exploitation.

Reports & references

  • cert.ssi.gouv.fr — Certfr 2025 Cti 009 (report)
  • meterpreter.org — Anssi Exposes Houken China Linked Apt Exploiting Ivanti Csa Zero Days Deploying Linux Rootkits (report)

External references