Feeds.Feedburner
Credential Theft Operation Poisson Targets French Business with Persistent Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A low-skilled attacker known as 'Poisson' executed a credential theft campaign against a small French automotive business, compromising four machines. The attack utilized a multi-stage malware chain, including a VBScript stager and a PowerShell loader, alongside a custom Python keylogger named Havoc. Poisson established persistent access using OpenSSH and Tailscale, allowing continued access even after command-and-control servers were disrupted. The operation was documented by Cato Networks, revealing the use of legitimate tools for malicious purposes. Keylogger deployment aimed to capture sensitive banking and email credentials. The attack emphasizes the need for organizations to monitor for unauthorized software installations and scheduled tasks. A full credential reset is recommended for all users affected by the keylogger. The incident highlights a critical security gap in detecting persistent access methods.
Key Points: • The attacker used OpenSSH and Tailscale for persistent access despite C2 disruptions. • Four machines were compromised in a small French automotive business. • A keylogger was deployed to capture sensitive credentials, necessitating a full credential reset.