Threats · 89 days ago
Killing the Havoc server did not end this intrusion because the operator had already planted a separate way back in. Once OpenSSH and Tailscale were on the victim host, command-and-control was no longer the only access path, so taking the malware beacon offline did not remove the attacker.
Cato says it tracked the Poisson intrusion for 33 days in a small French automotive business and saw the operator keep access after the Havoc outage. The session included banking and email credential theft, and the separate remote-access setup kept working even after the C2 disappeared and later returned. The lesson is simple: a clean C2 takedown does not mean the host is clean if attacker-added admin tools are still trusted on it.
1 source covering this story
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
Cato Networks tracked Poisson using OpenSSH and Tailscale to maintain access after Havoc C2 outage in a 33-day intrusion.
Part of the PlainSec briefing for 2026-06-18