THREAT INTELLIGENCE REPORT

Poisson Intrusion Campaign: Abuse of Tailscale and OpenSSH for Persistent Access

Analysis of a Junior Threat Actor Leveraging Legitimate Remote Access Tools to Maintain Persistence Beyond Command-and-Control Infrastructure Disruption

Analyst
Rajkumar G
Date
17 June 2026
Classification
Public
Report Type
Threat Intelligence

Executive Summary

Researchers observed a French-speaking threat actor known as "Poisson" compromise a small automotive business and maintain unauthorized access for more than a month. The attacker deployed a keylogger, harvested credentials, established persistence mechanisms, and abused legitimate remote administration tools including OpenSSH, Tailscale, and RustDesk.

The most significant finding was the attacker's use of Tailscale and OpenSSH to create an alternate access path independent of the Havoc command-and-control infrastructure. Even after the C2 server went offline, access to the victim environment remained intact through the attacker-controlled Tailscale network.

Key Intelligence Overview

Threat Actor

Poisson

Severity

High

Motivation

Credential Theft

C2 Framework

Havoc

Targets

Small Business

Confidence

High

Threat Actor Profile

The threat actor known as Poisson appears to be a relatively inexperienced cybercriminal operating primarily during afternoon and evening hours in Central European Time. Despite limited operational security and multiple mistakes, the attacker successfully compromised several systems using publicly available tools and low-cost infrastructure.

Campaign Timeline

Initial Compromise

Victim environment breached and malware deployment initiated.

Persistence Established

Scheduled tasks and process injection techniques deployed.

Credential Collection

Custom Python keylogger installed for harvesting credentials.

7 April 2026

OpenSSH Server and Tailscale installed for independent persistence.

8 April 2026

Havoc command-and-control infrastructure becomes unavailable.

26 April 2026

Havoc infrastructure returns and agents reconnect automatically.

1 May 2026

Final observed activity and operational cleanup.

Attack Chain Analysis

Initial Access

The exact intrusion vector remains unknown, but the attacker successfully gained access to victim systems and began executing malicious scripts.

Execution

A VBScript stager executed a PowerShell loader that downloaded a .NET loader responsible for running the Havoc Demon implant entirely in memory.

Privilege Escalation

The attacker attempted elevation using Windows User Account Control prompts through Start-Process with administrative execution requests.

Persistence

Persistence was achieved through scheduled tasks, process injection into Explorer.exe, RustDesk deployment, OpenSSH installation, and Tailscale network enrollment.

Credential Access

A custom Python keylogger captured user keystrokes and stored them locally for manual collection by the attacker.

Command and Control

The Havoc framework served as the primary command-and-control platform before the attacker established alternative access channels.

Long-Term Access

OpenSSH and Tailscale enabled direct access to victim systems even when command-and-control infrastructure became unavailable.

Tools and Infrastructure

Category Tool
C2 Framework Havoc
Remote Access RustDesk
VPN Access Tailscale
Remote Shell OpenSSH
DNS Service DuckDNS
Cloud Storage Backblaze B2
Hosting IONOS VPS

MITRE ATT&CK Mapping

Tactic Observed Technique
Execution PowerShell
Persistence Scheduled Task
Persistence Remote Services
Privilege Escalation Valid Accounts
Defense Evasion Process Injection
Credential Access Keylogging
Command and Control Application Layer Protocol
Exfiltration Manual Credential Collection

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Restrict unauthorized remote access software.
  2. Monitor installation of OpenSSH Server.
  3. Implement application allowlisting.
  4. Block unapproved VPN services.
  5. Audit scheduled tasks regularly.
  6. Enable PowerShell logging.
  7. Deploy endpoint detection and response solutions.
  8. Conduct threat hunting for persistence mechanisms.

Analyst Assessment

This campaign demonstrates that legitimate administrative tools can provide highly effective persistence. The attacker's most significant success was not malware deployment but the creation of alternative access channels using trusted software.

Organizations that focus solely on removing malware or disabling command-and-control infrastructure may overlook secondary persistence mechanisms that allow attackers to maintain long-term access.

Intelligence Sources

References

Share Report