HoukenHouken

Also known as: Houken

Known aliases
1

Profile

Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to critical infrastructure networks, particularly in France. The group employs a sophisticated rootkit alongside open-source tools, primarily developed by Chinese-speaking authors, to maintain persistence and control over compromised systems. Houken is suspected to operate as an initial access broker, selling footholds in targeted networks to other threat actors for further exploitation.

Aliases· 1

Houken

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
HAFNIUM
Actor
Worok
Actor
IronHusky
Actor
UNC5174
Actor
UNC2717
Software
Huigezi malware
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.