Threat Intelligence Attacker establishes persistent access to French business using OpenSSH and Tailscale June 18, 2026 Share By SC Staff A French-speaking attacker, known as "Poisson," targeted a small French automotive business, successfully compromising four machines despite exhibiting novice-level tradecraft. The operation, meticulously documented by Cato Networks, highlights a critical security gap where disabling command-and-control servers does not guarantee an attacker's removal if alternative persistent access methods are established, as reported by The Hacker News. The attacker utilized a multi-stage in-memory malware chain, including a VBScript stager, a PowerShell loader, and Havoc's Demon agent, to gain initial access. To ensure persistence, "Poisson" escalated privileges using a visible UAC prompt and established a scheduled task with the highest privileges. A keylogger was deployed to capture banking and email credentials. The most significant aspect of the attack was the attacker's installation of OpenSSH Server and Tailscale on a victim's machine, creating a covert access channel independent of the command-and-control server. Even after the Havoc infrastructure went offline, the attacker maintained access through this separate, encrypted mesh network. This tactic, combined with legitimate tools like RustDesk for a backup channel, underscores the challenge of detecting and remediating threats that leverage authorized software for malicious purposes. Source: The Hacker News SC Staff Related Threat Intelligence China-linked group uses InfiniteRed malware to target medical research institutions SC Staff June 15, 2026 The attackers, identified as UNC6508, likely exploited older, vulnerable versions of REDCap to gain initial access, although the exact method remains undetermined. Threat Intelligence FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage Laura French June 11, 2026 The sites were used to lure security clearance holders into divulging classified information. Threat Intelligence OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor SC Staff June 11, 2026 Vietnam-aligned threat actor OceanLotus has been linked to two distinct campaigns targeting domestic entities and stock investors with a backdoor known as SPECTRALVIPER, according to ESET. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Deauthentication Attack Deepfake Defacement Dictionary Attack Distributed Scans DumpSec Dumpster Diving Password Cracking Reconnaissance You can skip this ad in 5 seconds