Hacker's Secret Backdoor: How a Junior Attacker Maintained Access After C2 Server Shutdown (2026)

In the world of cybersecurity, the battle against sophisticated attackers is an ongoing struggle. The recent incident involving a junior hacker, known as Poisson, has shed light on a concerning trend: the use of legitimate tools for malicious purposes. This article delves into the fascinating and alarming details of this attack, offering a unique perspective on the challenges faced by cybersecurity professionals.

A Sneaky Intrusion

Poisson, a French-speaking attacker, executed a well-planned operation against a small French automotive business. The initial steps involved planting a keylogger to steal banking and email credentials. However, the real intrigue lies in the attacker's strategic move to ensure persistent access, even after the command-and-control (C2) server went offline.

What makes this case extraordinary is the attacker's decision to install OpenSSH and Tailscale on the victim's machine. This move created a separate, encrypted pathway for access, independent of the C2 infrastructure. By setting up a reverse tunnel and joining the victim's machine to his private Tailscale network, Poisson effectively built a backdoor that remained operational even when the C2 server was down.

The Power of Legitimate Tools

The use of legitimate tools like OpenSSH and Tailscale highlights a critical aspect of modern cyberattacks. These tools, designed for legitimate purposes, can be easily co-opted by attackers. As the article notes, China's APT31 has utilized Tailscale for quiet exfiltration from Russian IT firms, and the Scattered Spider has employed legitimate remote-access tools. The fact that these tools are signed and legitimate makes detection based on bad files, rather than behavior, a challenging task.

A Junior Operator's Journey

Poisson's tradecraft, while not sophisticated, reveals a junior operator's approach. His long midday gaps, use of free-tier services like DuckDNS and Backblaze B2, and the naming of storage buckets after his handle all add a layer of personal touch to the attack. Despite his mistakes, such as leaking his home directory and leaving test files, he successfully compromised four machines.

The Chain of Infection

The malware employed by Poisson was designed to run almost entirely in memory. A VBScript stager, with a sandbox-evasion delay, decrypted a PowerShell loader, which then pulled down a .NET loader to run the Havoc Demon agent. This process, while intricate, was not silent. The use of Start-Process -Verb RunAs for elevation, which prompts user consent, showcases the attacker's understanding of Windows security mechanisms.

The Crucial Move: Persistent Access

The key to Poisson's success lay in his ability to establish persistent access. On April 7, he installed OpenSSH Server and Tailscale, creating a reverse tunnel and joining the victim's machine to his private Tailscale network. This move ensured that even when the C2 server went offline, the attacker could still reach the machine over Tailscale's encrypted mesh.

The Remediation Challenge

The article emphasizes a critical lesson: pulling a C2 server offline is not sufficient remediation if the attacker has built a separate door. The presence of OpenSSH, Tailscale, the scheduled task, and the keylogger means that even if the C2 is taken down, the attacker can still regain access. This highlights the need for a comprehensive approach to remediation, one that addresses the underlying persistence mechanisms.

What to Watch For

Cato's hunting list provides valuable insights for cybersecurity professionals. By monitoring for specific indicators, such as OpenSSH Server installations, Tailscale usage on machines without a VPN, and reverse tunnels, security teams can detect and mitigate such attacks more effectively. Additionally, looking for WScript.exe running .vbs files and flagging scheduled tasks with high privileges can help identify potential compromises.

The Bigger Picture

The incident involving Poisson raises broader questions about the evolving nature of cyberattacks. The use of legitimate tools and the focus on persistent access are trends that cybersecurity professionals must address. As the article suggests, when a C2 is identified, it is essential to assume that it is not the only entry point and to actively hunt for the quiet persistence layer behind it.

The Unanswered Question

One intriguing question left unanswered is the content of Thales.zip and the purpose of the two programs that ran for 32 minutes on the machine. While the answer may not be immediately apparent, it is clear that the C2 was not the primary intrusion point. The real concern lies in the attacker's ability to maintain access through legitimate tools, even after the C2 is taken down.

In conclusion, the case of Poisson serves as a stark reminder of the evolving tactics employed by attackers. By understanding the intricacies of this attack and the challenges it presents, cybersecurity professionals can better prepare for and mitigate such threats. As the battle against cybercriminals continues, staying one step ahead requires a deep understanding of their methods and a commitment to comprehensive remediation strategies.

Hacker's Secret Backdoor: How a Junior Attacker Maintained Access After C2 Server Shutdown (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5564

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.