Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Posted on June 17, 2026 By CWS

A recent cybersecurity incident involving a junior hacker employing OpenSSH and Tailscale has raised concerns in the industry. This attacker, targeting a small French automotive company, initially managed to plant a keylogger and extract sensitive banking and email credentials. What seemed like an ordinary breach took an unexpected turn with the hacker’s strategic use of OpenSSH and Tailscale, allowing continued access even after the loss of a command-and-control (C2) server.

Hacker’s Innovative Approach

The attacker’s clever move came just before their C2 server went offline. By integrating OpenSSH and Tailscale into the compromised system, the hacker established a secure and independent access route. This move ensured that, even when the C2 infrastructure was deactivated, the attacker retained connectivity. After an 18-day hiatus, the C2 server was reactivated, and the hacker’s agents seamlessly reconnected, demonstrating the robustness of the alternative access pathway.

Researchers from Cato Networks documented this incident meticulously, capturing 339 commands over a span of 33 days. The operator, using the alias “Poisson,” inadvertently left behind crucial evidence such as SSH keys and operational instructions, providing a unique perspective into the hacker’s activities.

Analyzing the Hacker’s Operation

Despite being labeled as a junior operator, Poisson’s actions highlighted significant vulnerabilities. Operating primarily on free-tier services like DuckDNS and IONOS VPS, the hacker’s approach was marked by several missteps. Nevertheless, the attack compromised four machines, demonstrating the potential impact of even less sophisticated cybercriminals.

The attack chain was complex, involving malware that predominantly functioned in memory. Techniques included a VBScript stager to evade sandboxes, followed by a PowerShell loader to execute Havoc’s Demon agent. For privilege escalation, Poisson relied on a non-silent method, requiring user interaction to proceed, which took multiple attempts.

Security Implications and Recommendations

The case underlines crucial security lessons. As demonstrated, removing a C2 server is insufficient if alternative access routes like Tailscale exist. Security experts suggest monitoring for unusual installations such as OpenSSH on Windows workstations and vigilance for Tailscale or reverse SSH tunnels on systems without justified usage.

Additional recommendations include observing for specific script executions from user directories and high-privilege scheduled tasks. Changes in system settings that prevent machines from entering standby mode should also be flagged, alongside blocking services like DuckDNS which are often misused by attackers.

Ultimately, the incident emphasizes the need for comprehensive threat detection strategies that go beyond identifying malicious files to recognizing behavioral patterns indicative of persistent threats. While questions remain about the specifics of files like Thales.zip used in this breach, the broader lesson is clear: a C2 server takedown does not equate to complete remediation if alternative access points remain active.

The Hacker News Tags:C2 Server, Cato Networks, cyber attack, cyber threat, Cybersecurity, French automotive, Hacker, Keylogger, Malware, network security, OpenSSH, persistent access, Poisson, Tailscale

Post navigation

Previous Post: Fake Software Updates Target macOS Users for Data Theft
Next Post: Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking

Related Posts

Oracle Resolves Critical RCE Vulnerability in Identity Manager Oracle Resolves Critical RCE Vulnerability in Identity Manager The Hacker News
Critical Cisco Flaws Fixed: IMC and SSM Security Updates Critical Cisco Flaws Fixed: IMC and SSM Security Updates The Hacker News
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft The Hacker News
Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition The Hacker News
AI Hacking, Chrome Vulnerabilities, SonicWall Attacks AI Hacking, Chrome Vulnerabilities, SonicWall Attacks The Hacker News
Close Approval Gaps in AI Ad Tech with Our Webinar Close Approval Gaps in AI Ad Tech with Our Webinar The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark