C2 Takedown Left the Intrusion Alive

Killing the Havoc server did not end this intrusion because the operator had already planted a separate way back in. Once OpenSSH and Tailscale were on the victim host, command-and-control was no longer the only access path, so taking the malware beacon offline did not remove the attacker. Cato says it tracked the Poisson intrusion for 33 days in a small French automotive business and saw the operator keep access after the Havoc outage. The session included banking and email credential theft, and the separate remote-access setup kept working even after the C2 disappeared and later returned. The lesson is simple: a clean C2 takedown does not mean the host is clean if attacker-added admin tools are still trusted on it.

Part of the PlainSec briefing for 2026-06-18

Sources