Cato Networks detailed a 33-day intrusion by a French-speaking threat actor tracked as Poisson that targeted a small French automotive business and several French individuals, using 339 recorded commands recovered from an exposed Havoc command-and-control server. The attacker used a multi-stage fileless infection chain, scheduled-task persistence, Explorer.exe injection, a custom RustDesk deployment, and a simple Python keylogger to steal banking, email, and other credentials, while also enumerating certificate stores and manually collecting keystroke logs.
The most consequential step came when Poisson installed OpenSSH Server and Tailscale on a victim machine, configured key-based SSH and a reverse tunnel, and created a VPN-mesh-backed access path that remained active after the Havoc C2 went offline. When the infrastructure returned, the implants reconnected without the attacker needing to re-compromise the victims, showing how even a relatively low-skill operator using inexpensive services such as DuckDNS, Backblaze B2, and an IONOS VPS could preserve post-compromise access and continue credential-focused activity despite a C2 disruption.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
On June 16, 2026, Cato Networks published its analysis of Operation Poisson, detailing the actor's tooling, persistence methods, and the resilience provided by Tailscale and OpenSSH after the C2 outage. The report was based on 33 days of exposed command history from the actor's Havoc server.
Cato's observed 33-day command history from the Poisson operation ran through May 1, 2026. The captured dataset covered the actor's activity across the intrusion window from March 30 to May 1.
On April 26, 2026, the Havoc C2 infrastructure came back online and the implants reconnected automatically without the attacker needing to re-compromise victims. The actor then resumed credential-focused activity.
Beginning April 8, 2026, the Havoc command-and-control infrastructure went offline. Despite the outage, the attacker retained access through the previously established OpenSSH and Tailscale persistence.
On April 7, 2026, the attacker installed OpenSSH Server and Tailscale on a victim machine, configuring SSH access and a separate VPN-mesh-based persistence path. This created resilient access outside the primary Havoc C2 channel.
A French-speaking threat actor tracked as "Poisson" began a 33-day operation on March 30, 2026, targeting a small French automotive business and several French individuals. Cato later documented 339 commands from the actor's Havoc C2 activity during this period.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecatonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.