# Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion

> A French-speaking junior threat actor tracked as "Poisson" maintained access to a small French automotive business and four French individuals over a 33-day intrusion (March 30 - May 1, 2026) using the Havoc C2 framework (Demon agent). Before his C2 went offline he pre-positioned OpenSSH Server, a Tailscale mesh VPN and RustDesk so access survived an 18-day C2 outage and reconnected automatically. A Python pynput keylogger harvested banking and email credentials. Documented by Cato CTRL after the operator left SSH keys and a full playbook in an open Backblaze B2 bucket.

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0879
- **ID:** TL-2026-0879
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** Poisson
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Operation Poisson is a credential-theft intrusion attributed to a low-skilled, French-speaking operator (handles "Poisson" and "Stikou68", Linux user avenger@ubuntu) who, despite junior tradecraft, executed a resilient multi-stage in-memory attack chain and engineered C2-independent persistence that defeated infrastructure takedown.

The kill chain began with an AES-encrypted VBScript stager (sys.vbs, ~1.1 KB) that decrypted and launched a PowerShell loader, which retrieved senti.dll (3.1 MB) from a Backblaze B2 bucket. senti.dll is a four-layer "matryoshka" reflective-PE loader (Donut-style, XOR key 0x02) that encodes the Havoc Demon agent shellcode as 207,813 English words, then injects it into Explorer.EXE for fileless execution. The Demon agent beaconed over HTTPS to a Havoc teamserver (217.154.217.139) fronted by a redirector (217.154.162.45), both IONOS SE VPS hosts in Berlin sharing the TLS certificate CN wawsenti.duckdns.org.

Privilege escalation used Start-Process -Verb RunAs, relying on a visible UAC consent dialog; the operator failed roughly seven attempts on one victim before a user clicked through. Persistence was layered: a scheduled task TaskAdmin1 running at logon with highest privileges, a startup-folder shortcut (sys.lnk), and Explorer.EXE shellcode injection. RustDesk (custom-compiled with the operator's relay config) was added as a secondary remote-access channel with dedicated inbound/outbound firewall rules.

The pivotal move came on April 7 during a 5-hour overnight session: the operator installed OpenSSH Server (sshd, auto-start) and Tailscale VPN on a victim workstation, configured key-based SSH auth, joined the host to his Tailscale mesh, and established a reverse SSH tunnel (ssh -R). When the Havoc C2 went offline on April 8, this mesh-based access survived; when the C2 returned on April 26 after an 18-day outage, all victims were still compromised and the Demon agents reconnected automatically with no re-compromise required. A 70-line Python keylogger (pynput) written KeyL.zip captured keystrokes locally for manual retrieval, focused on banking credentials, email passwords and government-portal logins. powercfg /change standby-timeout-ac 300 kept machines awake, and certutil -scinfo was run repeatedly to enumerate certificate stores and smart-card information. On April 30 the operator ran late-stage tooling from Thales.zip (WinFormsApp1.exe, Thal.exe) and deleted 17 files; the last command was issued at 18:14 UTC, and the C2 went offline May 1.

Infrastructure was exclusively free-tier (DuckDNS dynamic DNS, Backblaze B2 storage, a cheap IONOS Berlin VPS), and severe OPSEC failures - leaking /home/avenger/Desktop/ five times, naming buckets after his handle, and exposing his complete SSH playbook, victim keys and French installation notes on a public Backblaze bucket - allowed Cato CTRL to reconstruct all 339 commands across the 33-day operation. The defining lesson: the C2 was never the intrusion, merely one door into it; killing the teamserver left OpenSSH, Tailscale, the scheduled task and the keylogger fully operational on a separate encrypted mesh.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1055 Process Injection
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1620 Reflective Code Loading
- T1070 Indicator Removal
- T1056 Input Capture
- T1087 Account Discovery
- T1082 System Information Discovery
- T1071 Application Layer Protocol
- T1219 Remote Access Tools
- T1572 Protocol Tunneling
- T1090 Proxy
- T1568 Dynamic Resolution
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Operation Poisson Under the Spotlight - Analyzing a Cybercriminal's Entire Operation](https://www.catonetworks.com/blog/cato-ctrl-operation-poisson-analyzing-a-cybercriminals-entire-operation/)
- [Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline](https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html)
- [Operation Poisson Exposes a Resilient Credential Theft Chain](https://socprime.com/active-threats/operation-poisson-breaking-down-an-entire-cybercriminal-operation/)
- [Attacker establishes persistent access to French business using OpenSSH and Tailscale](https://www.scworld.com/brief/attacker-establishes-persistent-access-to-french-business-using-openssh-and-tailscale)
- [Mesh Networks as Backdoors: How a Junior Threat Actor Bypassed C2 Detection with Tailscale and OpenSSH](https://news.shield53.com/mesh-networks-as-backdoors-how-a-junior-threat-actor-bypassed-c2-detection-with-tailscale-and-openssh/)
- [MITRE ATT&CK T1219 Remote Access Software](https://attack.mitre.org/techniques/T1219/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0879
