Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Posted on June 17, 2026 By CWS

A recent cybersecurity incident involving a junior hacker employing OpenSSH and Tailscale has raised concerns in the industry. This attacker, targeting a small French automotive company, initially managed to plant a keylogger and extract sensitive banking and email credentials. What seemed like an ordinary breach took an unexpected turn with the hacker’s strategic use of OpenSSH and Tailscale, allowing continued access even after the loss of a command-and-control (C2) server.

Hacker’s Innovative Approach

The attacker’s clever move came just before their C2 server went offline. By integrating OpenSSH and Tailscale into the compromised system, the hacker established a secure and independent access route. This move ensured that, even when the C2 infrastructure was deactivated, the attacker retained connectivity. After an 18-day hiatus, the C2 server was reactivated, and the hacker’s agents seamlessly reconnected, demonstrating the robustness of the alternative access pathway.

Researchers from Cato Networks documented this incident meticulously, capturing 339 commands over a span of 33 days. The operator, using the alias “Poisson,” inadvertently left behind crucial evidence such as SSH keys and operational instructions, providing a unique perspective into the hacker’s activities.

Analyzing the Hacker’s Operation

Despite being labeled as a junior operator, Poisson’s actions highlighted significant vulnerabilities. Operating primarily on free-tier services like DuckDNS and IONOS VPS, the hacker’s approach was marked by several missteps. Nevertheless, the attack compromised four machines, demonstrating the potential impact of even less sophisticated cybercriminals.

The attack chain was complex, involving malware that predominantly functioned in memory. Techniques included a VBScript stager to evade sandboxes, followed by a PowerShell loader to execute Havoc’s Demon agent. For privilege escalation, Poisson relied on a non-silent method, requiring user interaction to proceed, which took multiple attempts.

Security Implications and Recommendations

The case underlines crucial security lessons. As demonstrated, removing a C2 server is insufficient if alternative access routes like Tailscale exist. Security experts suggest monitoring for unusual installations such as OpenSSH on Windows workstations and vigilance for Tailscale or reverse SSH tunnels on systems without justified usage.

Additional recommendations include observing for specific script executions from user directories and high-privilege scheduled tasks. Changes in system settings that prevent machines from entering standby mode should also be flagged, alongside blocking services like DuckDNS which are often misused by attackers.

Ultimately, the incident emphasizes the need for comprehensive threat detection strategies that go beyond identifying malicious files to recognizing behavioral patterns indicative of persistent threats. While questions remain about the specifics of files like Thales.zip used in this breach, the broader lesson is clear: a C2 server takedown does not equate to complete remediation if alternative access points remain active.

The Hacker News Tags:C2 Server, Cato Networks, cyber attack, cyber threat, Cybersecurity, French automotive, Hacker, Keylogger, Malware, network security, OpenSSH, persistent access, Poisson, Tailscale

Post navigation

Previous Post: Fake Software Updates Target macOS Users for Data Theft
Next Post: Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking

Related Posts

Aurora Ransomware Leveraging AI in Cyber Attacks Aurora Ransomware Leveraging AI in Cyber Attacks The Hacker News
ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach The Hacker News
AI Agents Vulnerable to New Data Injection Attacks AI Agents Vulnerable to New Data Injection Attacks The Hacker News
Gitea Patches Critical RCE Vulnerability in Git Hooks Gitea Patches Critical RCE Vulnerability in Git Hooks The Hacker News
Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks The Hacker News
Why the New AI Browsers War is a Nightmare for Security Teams Why the New AI Browsers War is a Nightmare for Security Teams The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks
  • CISA and NIST Issue Guide to Strengthen Identity Token Security
  • Microsoft Sets New AI Privacy Standards for Schools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks
  • CISA and NIST Issue Guide to Strengthen Identity Token Security
  • Microsoft Sets New AI Privacy Standards for Schools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark