Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Posted on June 17, 2026 By CWS

A recent cybersecurity incident involving a junior hacker employing OpenSSH and Tailscale has raised concerns in the industry. This attacker, targeting a small French automotive company, initially managed to plant a keylogger and extract sensitive banking and email credentials. What seemed like an ordinary breach took an unexpected turn with the hacker’s strategic use of OpenSSH and Tailscale, allowing continued access even after the loss of a command-and-control (C2) server.

Hacker’s Innovative Approach

The attacker’s clever move came just before their C2 server went offline. By integrating OpenSSH and Tailscale into the compromised system, the hacker established a secure and independent access route. This move ensured that, even when the C2 infrastructure was deactivated, the attacker retained connectivity. After an 18-day hiatus, the C2 server was reactivated, and the hacker’s agents seamlessly reconnected, demonstrating the robustness of the alternative access pathway.

Researchers from Cato Networks documented this incident meticulously, capturing 339 commands over a span of 33 days. The operator, using the alias “Poisson,” inadvertently left behind crucial evidence such as SSH keys and operational instructions, providing a unique perspective into the hacker’s activities.

Analyzing the Hacker’s Operation

Despite being labeled as a junior operator, Poisson’s actions highlighted significant vulnerabilities. Operating primarily on free-tier services like DuckDNS and IONOS VPS, the hacker’s approach was marked by several missteps. Nevertheless, the attack compromised four machines, demonstrating the potential impact of even less sophisticated cybercriminals.

The attack chain was complex, involving malware that predominantly functioned in memory. Techniques included a VBScript stager to evade sandboxes, followed by a PowerShell loader to execute Havoc’s Demon agent. For privilege escalation, Poisson relied on a non-silent method, requiring user interaction to proceed, which took multiple attempts.

Security Implications and Recommendations

The case underlines crucial security lessons. As demonstrated, removing a C2 server is insufficient if alternative access routes like Tailscale exist. Security experts suggest monitoring for unusual installations such as OpenSSH on Windows workstations and vigilance for Tailscale or reverse SSH tunnels on systems without justified usage.

Additional recommendations include observing for specific script executions from user directories and high-privilege scheduled tasks. Changes in system settings that prevent machines from entering standby mode should also be flagged, alongside blocking services like DuckDNS which are often misused by attackers.

Ultimately, the incident emphasizes the need for comprehensive threat detection strategies that go beyond identifying malicious files to recognizing behavioral patterns indicative of persistent threats. While questions remain about the specifics of files like Thales.zip used in this breach, the broader lesson is clear: a C2 server takedown does not equate to complete remediation if alternative access points remain active.

The Hacker News Tags:C2 Server, Cato Networks, cyber attack, cyber threat, Cybersecurity, French automotive, Hacker, Keylogger, Malware, network security, OpenSSH, persistent access, Poisson, Tailscale

Post navigation

Previous Post: Fake Software Updates Target macOS Users for Data Theft
Next Post: Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking

Related Posts

Microsoft Unveils Phishing Scheme Affecting Thousands Globally Microsoft Unveils Phishing Scheme Affecting Thousands Globally The Hacker News
A 24-Hour Timeline of a Modern Stealer Campaign A 24-Hour Timeline of a Modern Stealer Campaign The Hacker News
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages The Hacker News
[Webinar] Shadow AI Agents Multiply Fast — Learn How to Detect and Control Them [Webinar] Shadow AI Agents Multiply Fast — Learn How to Detect and Control Them The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News
ShowDoc Vulnerability CVE-2025-0520 Exploited in the Wild ShowDoc Vulnerability CVE-2025-0520 Exploited in the Wild The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Crypto Malware Campaign Exploits Fake Reviews and AI
  • GitBait Exploits GitHub Pages in Financial Sector Attacks
  • Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking
  • Junior Hacker’s Persistent Access via OpenSSH and Tailscale
  • Fake Software Updates Target macOS Users for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Crypto Malware Campaign Exploits Fake Reviews and AI
  • GitBait Exploits GitHub Pages in Financial Sector Attacks
  • Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking
  • Junior Hacker’s Persistent Access via OpenSSH and Tailscale
  • Fake Software Updates Target macOS Users for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark