Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion — Threadlinqs Intelligence
As of 2026-06-19, Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion is a high-severity threat intel threat attributed to Poisson, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-0879 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Poisson · FINANCIAL
A French-speaking junior threat actor tracked as "Poisson" maintained access to a small French automotive business and four French individuals over a 33-day intrusion (March 30 - May 1, 2026) using
Operation Poisson is a credential-theft intrusion attributed to a low-skilled, French-speaking operator (handles "Poisson" and "Stikou68", Linux user avenger@ubuntu) who, despite junior tradecraft, executed a resilient multi-stage in-memory attack chain and engineered C2-independent persistence that defeated infrastructure takedown.
The kill chain began with an AES-encrypted VBScript stager (sys.vbs, ~1.1 KB) that decrypted and launched a PowerShell loader, which retrieved senti.dll (3.1 MB) from a Backblaze B2 bucket. senti.dll is a four-layer "matryoshka" reflective-PE loader (Donut-style, XOR key 0x02) that encodes the Havoc Demon agent shellcode as 207,813 English words, then injects it into Explorer.EXE for fileless execution. The Demon agent beaconed over HTTPS to a Havoc teamserver (217.154.217.139) fronted by a redirector (217.154.162.45), both IONOS SE VPS hosts in Berlin sharing the TLS certificate CN wawsenti.duckdns.org.
Privilege escalation used Start-Process -Verb RunAs, relying on a visible UAC consent dialog; the operator failed roughly seven attempts on one victim before a user clicked through. Persistence was layered: a scheduled task TaskAdmin1 running at logon with highest privileges, a startup-folder shortcut (sys.lnk), and Explorer.EXE shellcode injection. RustDesk (custom-compiled with the operator's relay config) was added as a secondary remote-access channel with dedicated inbound/outbound firewall rules.
The pivotal move came on April 7 during a 5-hour overnight session: the operator installed OpenSSH Server (sshd, auto-start) and Tailscale VPN on a victim workstation, configured key-based SSH auth, joined the host to his Tailscale mesh, and established a reverse SSH tunnel (ssh -R). When the Havoc C2 went offline on April 8, this mesh-based access survived; when the C2 returned on April 26 after an 18-day outage, all victims were still compromised and the Demon agents reconnected automatically with no re-compromise required. A 70-line Python keylogger (pynput) written KeyL.zip captured keystrokes locally for manual retrieval, focused on banking credentials, email passwords and government-portal logins. powercfg /change standby-timeout-ac 300 kept machines awake, and certutil -scinfo was run repeatedly to enumerate certificate stores and smart-card information. On April 30 the operator ran late-stage tooling from Thales.zip (WinFormsApp1.exe, Thal.exe) and deleted 17 files; the last command was issued at 18:14 UTC, and the C2 went offline May 1.
Infrastructure was exclusively free-tier (DuckDNS dynamic DNS, Backblaze B2 storage, a cheap IONOS Berlin VPS), and severe OPSEC failures - leaking /home/avenger/Desktop/ five times, naming buckets after his handle, and exposing his complete SSH playbook, victim keys and French installation notes on a public Backblaze bucket - allowed Cato CTRL to reconstruct all 339 commands across the 33-day operation. The defining lesson: the C2 was never the intrusion, merely one door into it; killing the teamserver left OpenSSH, Tailscale, the scheduled task and the keylogger fully operational on a separate encrypted mesh.
Target sectors: automotive, individuals, consumer
Target regions: France, Europe
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1583, T1588, T1059, T1204, T1053, T1547, T1543, T1548, T1055, T1140