Skip to content
Credential Theft Operation Poisson Targets French Business with Persistent Access

Credential Theft Operation Poisson Targets French Business with Persistent Access

First seen 18 Jun 2026, 18:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 18:23 UTC
  • The attacker used OpenSSH and Tailscale for persistent access despite C2 disruptions.
  • Four machines were compromised in a small French automotive business.
  • A keylogger was deployed to capture sensitive credentials, necessitating a full credential reset.

A low-skilled attacker known as 'Poisson' executed a credential theft campaign against a small French automotive business, compromising four machines. The attack utilized a multi-stage malware chain, including a VBScript stager and a PowerShell loader, alongside a custom Python keylogger named Havoc. Poisson established persistent access using OpenSSH and Tailscale, allowing continued access even after command-and-control servers were disrupted. The operation was documented by Cato Networks, revealing the use of legitimate tools for malicious purposes. Keylogger deployment aimed to capture sensitive banking and email credentials. The attack emphasizes the need for organizations to monitor for unauthorized software installations and scheduled tasks. A full credential reset is recommended for all users affected by the keylogger. The incident highlights a critical security gap in detecting persistent access methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2026-06-17
Operation Poisson detailed by Cato Networks
Cato Networks published findings on the Poisson operation, revealing the attack methods and persistence techniques used.
Socprime
2026-06-18
Further reporting on Poisson's tactics
The Hacker News reported on the attacker's use of legitimate tools for malicious purposes and the impact on the automotive business.
Feeds.Feedburner

More articles in this cluster (2)

Following this threat?

Track Havoc and Ionos in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed