Feeds.Feedburner Credential Theft Operation Poisson Targets French Business with Persistent Access
Article Content
- •The attacker used OpenSSH and Tailscale for persistent access despite C2 disruptions.
- •Four machines were compromised in a small French automotive business.
- •A keylogger was deployed to capture sensitive credentials, necessitating a full credential reset.
A low-skilled attacker known as 'Poisson' executed a credential theft campaign against a small French automotive business, compromising four machines. The attack utilized a multi-stage malware chain, including a VBScript stager and a PowerShell loader, alongside a custom Python keylogger named Havoc. Poisson established persistent access using OpenSSH and Tailscale, allowing continued access even after command-and-control servers were disrupted. The operation was documented by Cato Networks, revealing the use of legitimate tools for malicious purposes. Keylogger deployment aimed to capture sensitive banking and email credentials. The attack emphasizes the need for organizations to monitor for unauthorized software installations and scheduled tasks. A full credential reset is recommended for all users affected by the keylogger. The incident highlights a critical security gap in detecting persistent access methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Havoc and Ionos in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New Exploits Target Microsoft SQL Server and SQL Injection Vulnerabilities Two new cybersecurity tools, MSSQLand and SQLMate, have been released targeting Microsoft SQL Server and SQL injection vulnerabilities respectively. MSSQLand is a post-exploitation tool designed for red team operators to navigate and exploit SQL Server environments with minimal detection. It allows for cascading…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…