Threat reportThreat IntelligenceTL-2026-0879

Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion

highACTIVE

Operation Poisson (TL-2026-0879), also tracked as Operation Poisson, is a high-severity tracked intrusion set, first published 2026-06-19. It is attributed to Poisson with low confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1027, T1041, T1053), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1Poisson
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-0879

Threat ID
TL-2026-0879
Also known as
Operation Poisson
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
Poisson
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
automotive, individuals, consumer
Target regions
France, Europe
Detection rules
9
Indicators of compromise
28

Malware and tooling in Operation Poisson

Malware and tooling: Havoc (Demon agent), OpenSSH Server (sshd), RustDesk, Tailscale

How Operation Poisson works

A French-speaking junior threat actor tracked as "Poisson" maintained access to a small French automotive business and four French individuals over a 33-day intrusion (March 30 - May 1, 2026) using the Havoc C2 framework (Demon agent). Before his C2 went offline he pre-positioned OpenSSH Server, a Tailscale mesh VPN and RustDesk so access survived an 18-day C2 outage and reconnected automatically. A Python pynput keylogger harvested banking and email credentials. Documented by Cato CTRL after the operator left SSH keys and a full playbook in an open Backblaze B2 bucket.

Operation Poisson is a credential-theft intrusion attributed to a low-skilled, French-speaking operator (handles "Poisson" and "Stikou68", Linux user avenger@ubuntu) who, despite junior tradecraft, executed a resilient multi-stage in-memory attack chain and engineered C2-independent persistence that defeated infrastructure takedown.

The kill chain began with an AES-encrypted VBScript stager (sys.vbs, ~1.1 KB) that decrypted and launched a PowerShell loader, which retrieved senti.dll (3.1 MB) from a Backblaze B2 bucket. senti.dll is a four-layer "matryoshka" reflective-PE loader (Donut-style, XOR key 0x02) that encodes the Havoc Demon agent shellcode as 207,813 English words, then injects it into Explorer.EXE for fileless execution. The Demon agent beaconed over HTTPS to a Havoc teamserver (217.154.217.139) fronted by a redirector (217.154.162.45), both IONOS SE VPS hosts in Berlin sharing the TLS certificate CN wawsenti.duckdns.org.

Privilege escalation used Start-Process -Verb RunAs, relying on a visible UAC consent dialog; the operator failed roughly seven attempts on one victim before a user clicked through. Persistence was layered: a scheduled task TaskAdmin1 running at logon with highest privileges, a startup-folder shortcut (sys.lnk), and Explorer.EXE shellcode injection. RustDesk (custom-compiled with the operator's relay config) was added as a secondary remote-access channel with dedicated inbound/outbound firewall rules.

The pivotal move came on April 7 during a 5-hour overnight session: the operator installed OpenSSH Server (sshd, auto-start) and Tailscale VPN on a victim workstation, configured key-based SSH auth, joined the host to his Tailscale mesh, and established a reverse SSH tunnel (ssh -R). When the Havoc C2 went offline on April 8, this mesh-based access survived; when the C2 returned on April 26 after an 18-day outage, all victims were still compromised and the Demon agents reconnected automatically with no re-compromise required. A 70-line Python keylogger (pynput) written KeyL.zip captured keystrokes locally for manual retrieval, focused on banking credentials, email passwords and government-portal logins. powercfg /change standby-timeout-ac 300 kept machines awake, and certutil -scinfo was run repeatedly to enumerate certificate stores and smart-card information. On April 30 the operator ran late-stage tooling from Thales.zip (WinFormsApp1.exe, Thal.exe) and deleted 17 files; the last command was issued at 18:14 UTC, and the C2 went offline May 1.

Infrastructure was exclusively free-tier (DuckDNS dynamic DNS, Backblaze B2 storage, a cheap IONOS Berlin VPS), and severe OPSEC failures - leaking /home/avenger/Desktop/ five times, naming buckets after his handle, and exposing his complete SSH playbook, victim keys and French installation notes on a public Backblaze bucket - allowed Cato CTRL to reconstruct all 339 commands across the 33-day operation. The defining lesson: the C2 was never the intrusion, merely one door into it; killing the teamserver left OpenSSH, Tailscale, the scheduled task and the keylogger fully operational on a separate encrypted mesh.

MITRE ATT&CK techniques used in TL-2026-0879

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Credential Access

T1056 Input Capture

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1568 Dynamic Resolution; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery; T1087 Account Discovery

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Affected products and versions in Operation Poisson

  • Microsoft — Windows
    Vulnerable versions: Windows 10/11 workstations (abused via legitimate features: OpenSSH Server, scheduled tasks, Explorer.EXE)
  • Tailscale — Tailscale VPN
    Vulnerable versions: abused as legitimate mesh-VPN persistence channel
  • RustDesk — RustDesk
    Vulnerable versions: custom-compiled build abused as backup remote access

Remediation for Operation Poisson

Immediate actions

  • Block DNS resolution of wawsenti[.]duckdns[.]org and DuckDNS subdomains not required for business
  • Block/deny the C2 IPs 217.154.217.139 and 217.154.162.45 (IONOS Berlin) at the perimeter
  • Block the three Backblaze B2 staging hosts (pois43, w456w5, sentiwaw on s3.eu-central-003.backblazeb2.com) used to deliver senti.dll and tooling
  • Hunt for and remove the TaskAdmin1 scheduled task and sys.lnk startup shortcut
  • Identify and remove unauthorized OpenSSH Server (sshd), Tailscale and RustDesk installs on workstations; revoke the operator's Ed25519 SSH key and any authorized_keys entries

Workarounds

  • Enforce UAC at the highest level and educate users not to approve unexpected RunAs consent prompts
  • Egress filtering to flag SSH reverse tunnels (ssh -R) and unexpected Tailscale/WireGuard mesh egress from workstations
  • Disable or restrict certutil and powercfg via application control where not operationally needed

Longer-term hardening

  • Alert on OpenSSH Server / Tailscale / RustDesk installation on endpoints where they are not sanctioned (living-off-trusted-tools)
  • Deploy EDR with behavioral detection for shellcode injection into Explorer.EXE and reflective PE loading
  • Restrict and monitor scheduled-task creation with -RunLevel Highest invoking script interpreters
  • Application control to block wscript.exe executing .vbs from user staging/temp directories

Timeline of Operation Poisson

  • Initial compromise of Victim 1 (French automotive small business); escalation to admin, TaskAdmin1 scheduled task deployed, RustDesk installed.
  • Persistence planted on a third victim: startup shortcut (sys.lnk) and Explorer.EXE shellcode injection.
  • 51 commands executed; ~7 failed Start-Process -Verb RunAs UAC bypass attempts before a user clicked the consent dialog, granting elevation.
  • KeyL.zip Python pynput keylogger deployed; manual keystroke retrieval begins (~3,000 characters captured by day 3).
  • Maintenance; a fourth French victim briefly registers (hostname carries '95' Val-d'Oise departement identifier).
  • 5-hour overnight session: OpenSSH Server (sshd) and Tailscale VPN installed, key-based SSH auth configured, host joined operator's Tailscale mesh, reverse tunnel (ssh -R) tested - C2-independent persistence established.
  • Havoc C2 teamserver goes offline; Tailscale/OpenSSH mesh persistence survives the takedown.
  • C2 returns after an 18-day outage; all victims still compromised and Demon agents reconnect automatically with no re-compromise.
  • Thales.zip accessed; WinFormsApp1.exe and Thal.exe executed (~32 minutes combined); 17 files deleted; last command issued at 18:14 UTC.
  • C2 goes offline and operations cease; 33-day intrusion with 339 recorded commands.
  • Cato CTRL (researcher Vitaly Simonovich) publishes the full operation reconstruction from the operator's exposed SSH keys and playbook in an open Backblaze B2 bucket.

Sources cited for Operation Poisson

Detection coverage for TL-2026-0879

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0879 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats