Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
ID: fcd1c070-9ee7-51f1-af09-edaca3ef562d
STIX ID: report--fcd1c070-9ee7-51f1-af09-edaca3ef562d
Feed Name: The Hacker News
Cato Networks obtained a 33-day, command-level record of an intrusion by an operator called "Poisson" who compromised multiple Windows hosts at a small French business, deployed an in-memory Havoc Demon implant and a 70-line Python keylogger to harvest credentials, and then installed OpenSSH and Tailscale to create a resilient, out-of-band access channel that persisted after the Havoc C2 was taken offline; the report emphasizes that legitimate-signed tools and VPN/SSH tunnels can bypass file-based detection and that takedown of visible C2 does not ensure remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
