Poisson is a French-speaking threat actor associated with opportunistic credential-focused intrusions against French targets, including a small automotive business and individual victims in France. The actor has been characterized as relatively low skill or junior in tradecraft, but still capable of achieving durable compromise across multiple systems through persistence, credential theft, and abuse of legitimate remote-access software. Observed activity shows Poisson using a multi-stage, largely in-memory infection chain involving a VBScript stager, a PowerShell loader, and the Havoc Demon agent. Post-compromise behavior included privilege escalation attempts via user-approved elevation prompts, persistence through scheduled tasks configured for high privileges, startup persistence, and shellcode injection into Explorer. The actor also deployed a Python-based keylogger to capture banking and email credentials and manually collected the resulting keystroke logs. A notable aspect of Poisson’s operations is the establishment of resilient alternate access paths independent of primary command-and-control infrastructure. The actor installed OpenSSH Server and Tailscale on a victim machine, configured key-based SSH access and reverse tunneling, and used RustDesk as an additional remote-access mechanism. This allowed continued access even after the Havoc infrastructure became unavailable, demonstrating practical persistence and post-exploitation capability despite otherwise unsophisticated tradecraft. Additional observed actions included keeping victim systems awake to support credential harvesting and enumerating certificate stores and smart-card-related information. Poisson’s activity is consistent with financially motivated cybercrime centered on credential theft and sustained unauthorized access rather than espionage or destructive operations. No high-confidence evidence supports attribution to a nation state.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted a small French automotive business using a multi-stage in-memory intrusion chain, credential theft, privilege escalation, persistence via scheduled tasks, and covert persistent remote access through OpenSSH Server, Tailscale, and RustDesk.
Credential-theft campaign targeting French individuals and a French automotive small business using a multi-stage fileless Havoc-based intrusion, persistence via scheduled tasks and startup items, a Python keylogger, and resilient post-takedown access through OpenSSH and Tailscale VPN mesh.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.