Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation
ID: 629f862d-f648-5599-9dcd-f9fe141cc27c
STIX ID: report--629f862d-f648-5599-9dcd-f9fe141cc27c
Feed Name: Cato Networks
Cato CTRL analyzed a 33-day intrusion by a French-speaking operator (“Poisson”) who used a Havoc C2, multi-stage fileless loaders, a 70-line Python keylogger, and OpenSSH + Tailscale VPN to harvest credentials from one automotive small business and four individuals; the actor’s Tailscale/SSH persistence kept access alive after the C2 was taken down, demonstrating VPN-mesh-based persistence is in active use. The report provides a day-by-day reconstruction, kill chain, IoCs (IPs, Backblaze buckets, SHA256s, scheduled task, services), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
