Threat reportThreat IntelligenceTL-2026-0879
Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion
Operation Poisson (TL-2026-0879), also tracked as Operation Poisson, is a high-severity tracked intrusion set, first published 2026-06-19. It is attributed to Poisson with low confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1027, T1041, T1053), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1Poisson
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0879
- Threat ID
- TL-2026-0879
- Also known as
- Operation Poisson
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- Poisson
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- automotive, individuals, consumer
- Target regions
- France, Europe
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Operation Poisson
Malware and tooling: Havoc (Demon agent), OpenSSH Server (sshd), RustDesk, Tailscale
How Operation Poisson works
A French-speaking junior threat actor tracked as "Poisson" maintained access to a small French automotive business and four French individuals over a 33-day intrusion (March 30 - May 1, 2026) using the Havoc C2 framework (Demon agent). Before his C2 went offline he pre-positioned OpenSSH Server, a Tailscale mesh VPN and RustDesk so access survived an 18-day C2 outage and reconnected automatically. A Python pynput keylogger harvested banking and email credentials. Documented by Cato CTRL after the operator left SSH keys and a full playbook in an open Backblaze B2 bucket.
Operation Poisson is a credential-theft intrusion attributed to a low-skilled, French-speaking operator (handles "Poisson" and "Stikou68", Linux user avenger@ubuntu) who, despite junior tradecraft, executed a resilient multi-stage in-memory attack chain and engineered C2-independent persistence that defeated infrastructure takedown.
The kill chain began with an AES-encrypted VBScript stager (sys.vbs, ~1.1 KB) that decrypted and launched a PowerShell loader, which retrieved senti.dll (3.1 MB) from a Backblaze B2 bucket. senti.dll is a four-layer "matryoshka" reflective-PE loader (Donut-style, XOR key 0x02) that encodes the Havoc Demon agent shellcode as 207,813 English words, then injects it into Explorer.EXE for fileless execution. The Demon agent beaconed over HTTPS to a Havoc teamserver (217.154.217.139) fronted by a redirector (217.154.162.45), both IONOS SE VPS hosts in Berlin sharing the TLS certificate CN wawsenti.duckdns.org.
Privilege escalation used Start-Process -Verb RunAs, relying on a visible UAC consent dialog; the operator failed roughly seven attempts on one victim before a user clicked through. Persistence was layered: a scheduled task TaskAdmin1 running at logon with highest privileges, a startup-folder shortcut (sys.lnk), and Explorer.EXE shellcode injection. RustDesk (custom-compiled with the operator's relay config) was added as a secondary remote-access channel with dedicated inbound/outbound firewall rules.
The pivotal move came on April 7 during a 5-hour overnight session: the operator installed OpenSSH Server (sshd, auto-start) and Tailscale VPN on a victim workstation, configured key-based SSH auth, joined the host to his Tailscale mesh, and established a reverse SSH tunnel (ssh -R). When the Havoc C2 went offline on April 8, this mesh-based access survived; when the C2 returned on April 26 after an 18-day outage, all victims were still compromised and the Demon agents reconnected automatically with no re-compromise required. A 70-line Python keylogger (pynput) written KeyL.zip captured keystrokes locally for manual retrieval, focused on banking credentials, email passwords and government-portal logins. powercfg /change standby-timeout-ac 300 kept machines awake, and certutil -scinfo was run repeatedly to enumerate certificate stores and smart-card information. On April 30 the operator ran late-stage tooling from Thales.zip (WinFormsApp1.exe, Thal.exe) and deleted 17 files; the last command was issued at 18:14 UTC, and the C2 went offline May 1.
Infrastructure was exclusively free-tier (DuckDNS dynamic DNS, Backblaze B2 storage, a cheap IONOS Berlin VPS), and severe OPSEC failures - leaking /home/avenger/Desktop/ five times, naming buckets after his handle, and exposing his complete SSH playbook, victim keys and French installation notes on a public Backblaze bucket - allowed Cato CTRL to reconstruct all 339 commands across the 33-day operation. The defining lesson: the C2 was never the intrusion, merely one door into it; killing the teamserver left OpenSSH, Tailscale, the scheduled task and the keylogger fully operational on a separate encrypted mesh.
MITRE ATT&CK techniques used in TL-2026-0879
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Credential Access
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1568 Dynamic Resolution; T1572 Protocol Tunneling
Discovery
T1082 System Information Discovery; T1087 Account Discovery
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
Affected products and versions in Operation Poisson
- Microsoft — Windows
Vulnerable versions: Windows 10/11 workstations (abused via legitimate features: OpenSSH Server, scheduled tasks, Explorer.EXE) - Tailscale — Tailscale VPN
Vulnerable versions: abused as legitimate mesh-VPN persistence channel - RustDesk — RustDesk
Vulnerable versions: custom-compiled build abused as backup remote access
Remediation for Operation Poisson
Immediate actions
- Block DNS resolution of wawsenti[.]duckdns[.]org and DuckDNS subdomains not required for business
- Block/deny the C2 IPs 217.154.217.139 and 217.154.162.45 (IONOS Berlin) at the perimeter
- Block the three Backblaze B2 staging hosts (pois43, w456w5, sentiwaw on s3.eu-central-003.backblazeb2.com) used to deliver senti.dll and tooling
- Hunt for and remove the TaskAdmin1 scheduled task and sys.lnk startup shortcut
- Identify and remove unauthorized OpenSSH Server (sshd), Tailscale and RustDesk installs on workstations; revoke the operator's Ed25519 SSH key and any authorized_keys entries
Workarounds
- Enforce UAC at the highest level and educate users not to approve unexpected RunAs consent prompts
- Egress filtering to flag SSH reverse tunnels (ssh -R) and unexpected Tailscale/WireGuard mesh egress from workstations
- Disable or restrict certutil and powercfg via application control where not operationally needed
Longer-term hardening
- Alert on OpenSSH Server / Tailscale / RustDesk installation on endpoints where they are not sanctioned (living-off-trusted-tools)
- Deploy EDR with behavioral detection for shellcode injection into Explorer.EXE and reflective PE loading
- Restrict and monitor scheduled-task creation with -RunLevel Highest invoking script interpreters
- Application control to block wscript.exe executing .vbs from user staging/temp directories
Timeline of Operation Poisson
- Initial compromise of Victim 1 (French automotive small business); escalation to admin, TaskAdmin1 scheduled task deployed, RustDesk installed.
- Persistence planted on a third victim: startup shortcut (sys.lnk) and Explorer.EXE shellcode injection.
- 51 commands executed; ~7 failed Start-Process -Verb RunAs UAC bypass attempts before a user clicked the consent dialog, granting elevation.
- KeyL.zip Python pynput keylogger deployed; manual keystroke retrieval begins (~3,000 characters captured by day 3).
- Maintenance; a fourth French victim briefly registers (hostname carries '95' Val-d'Oise departement identifier).
- 5-hour overnight session: OpenSSH Server (sshd) and Tailscale VPN installed, key-based SSH auth configured, host joined operator's Tailscale mesh, reverse tunnel (ssh -R) tested - C2-independent persistence established.
- Havoc C2 teamserver goes offline; Tailscale/OpenSSH mesh persistence survives the takedown.
- C2 returns after an 18-day outage; all victims still compromised and Demon agents reconnect automatically with no re-compromise.
- Thales.zip accessed; WinFormsApp1.exe and Thal.exe executed (~32 minutes combined); 17 files deleted; last command issued at 18:14 UTC.
- C2 goes offline and operations cease; 33-day intrusion with 339 recorded commands.
- Cato CTRL (researcher Vitaly Simonovich) publishes the full operation reconstruction from the operator's exposed SSH keys and playbook in an open Backblaze B2 bucket.
Sources cited for Operation Poisson
- Operation Poisson Under the Spotlight - Analyzing a Cybercriminal's Entire Operation
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
- Operation Poisson Exposes a Resilient Credential Theft Chain
- Attacker establishes persistent access to French business using OpenSSH and Tailscale
- Mesh Networks as Backdoors: How a Junior Threat Actor Bypassed C2 Detection with Tailscale and OpenSSH
- MITRE ATT&CK T1219 Remote Access Software
Detection coverage for TL-2026-0879
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0879 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.