logo

Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation

ID: 629f862d-f648-5599-9dcd-f9fe141cc27c

STIX ID: report--629f862d-f648-5599-9dcd-f9fe141cc27c

Feed Name: Cato Networks

Threat Score
65/100

Date Published: 2026-06-16

Date Updated: 2026-07-23

Author: Tal Biran

...
...

Cato CTRL analyzed a 33-day intrusion by a French-speaking operator (“Poisson”) who used a Havoc C2, multi-stage fileless loaders, a 70-line Python keylogger, and OpenSSH + Tailscale VPN to harvest credentials from one automotive small business and four individuals; the actor’s Tailscale/SSH persistence kept access alive after the C2 was taken down, demonstrating VPN-mesh-based persistence is in active use. The report provides a day-by-day reconstruction, kill chain, IoCs (IPs, Backblaze buckets, SHA256s, scheduled task, services), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.