Credential Theft Operation Poisson Targets French Business with Persistent Access

Credential Theft Operation Poisson Targets French Business with Persistent Access

First seen 18 Jun 2026, 18:24 UTC SocprimeFeeds.Feedburner 81% similarity 54.9

Article Content

Browse articles
ThreatCluster

A low-skilled attacker known as 'Poisson' executed a credential theft campaign against a small French automotive business, compromising four machines. The attack utilized a multi-stage malware chain, including a VBScript stager and a PowerShell loader, alongside a custom Python keylogger named Havoc. Poisson established persistent access using OpenSSH and Tailscale, allowing continued access even after command-and-control servers were disrupted. The operation was documented by Cato Networks, revealing the use of legitimate tools for malicious purposes. Keylogger deployment aimed to capture sensitive banking and email credentials. The attack emphasizes the need for organizations to monitor for unauthorized software installations and scheduled tasks. A full credential reset is recommended for all users affected by the keylogger. The incident highlights a critical security gap in detecting persistent access methods.

Key Points: • The attacker used OpenSSH and Tailscale for persistent access despite C2 disruptions. • Four machines were compromised in a small French automotive business. • A keylogger was deployed to capture sensitive credentials, necessitating a full credential reset.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
Operation Poisson detailed by Cato Networks
Cato Networks published findings on the Poisson operation, revealing the attack methods and persistence techniques used.
Socprime
2026-06-18
Further reporting on Poisson's tactics
The Hacker News reported on the attacker's use of legitimate tools for malicious purposes and the impact on the automotive business.
Feeds.Feedburner

Community

Browse all →

Tracked Entities in This Story