Threats & Adversaries · Credential Theft

C2 Takedown Left the Intrusion Alive

Killing the Havoc server did not end this intrusion because the operator had already planted a separate way back in. Once OpenSSH and Tailscale were on the victim host, command-and-control was no longer the only access path, so taking the malware beacon offline did not remove the attacker.

Cato says it tracked the Poisson intrusion for 33 days in a small French automotive business and saw the operator keep access after the Havoc outage. The session included banking and email credential theft, and the separate remote-access setup kept working even after the C2 disappeared and later returned. The lesson is simple: a clean C2 takedown does not mean the host is clean if attacker-added admin tools are still trusted on it.

1 source · Jun 17

Timeline

Sources

Part of the PlainSec briefing for 2026-06-17

Every edition of this story: C2 Takedown Left the Intrusion Alive

More from today