BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Attackers Outlive Takedowns with SSH, Tailscale

Persistent attackers use legitimate tools as backup after C2 takedowns

  • Attackers can maintain access after C2 takedowns by installing separate persistence tools like OpenSSH and VPN software.
  • A junior hacker used free-tier services and a visible playbook but still successfully stole credentials from multiple machines.
  • The key threat involves legitimate, signed tools like Tailscale and RustDesk evading traditional file-based detection.
  • Effective remediation requires hunting for the secondary, quiet persistence layer behind any discovered command-and-control server.

A junior French-speaking hacker, operating after school hours, successfully breached a small French automotive business over 33 days, according to a detailed analysis by Cato Networks. The operator, using the handle “Poisson,” planted a keylogger and stole banking and email credentials using free infrastructure.

- Advertisement -

However, a critical move ensured his access outlived his primary attack server. He installed OpenSSH and Tailscale on a victim’s machine, creating an independent backdoor.

Consequently, when his Havoc command-and-control server went offline the next day, his access persisted for 18 days via the Tailscale network. The agents automatically reconnected when the C2 returned, allowing the operation to continue.

Researchers captured 339 commands after the operator leaked his SSH keys and a playbook. His tradecraft was described as thin, frequently failing and leaking his own data.

Meanwhile, the malware chain relied heavily on in-memory execution. A VBScript stager led to a PowerShell loader, which deployed the Havoc’s Demon agent without touching disk.

- Advertisement -

For persistence, he set a scheduled task and used a custom RustDesk instance. The keylogger was a simple Python script, with keystrokes harvested manually after using powercfg to keep systems awake.

Ultimately, the incident underscores that pulling a C2 offline is insufficient remediation. Cato Networks recommends specific hunts for OpenSSH installs, tailscale.exe, and reverse SSH tunnels on unauthorized workstations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Senate GOP Updated Clarity Act Targets Fake DeFi, Vote Set

Senate Republicans released an updated Clarity Act on Thursday targeting non-decentralized crypto trading protocols.The...

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

AI Leaves Banks Minutes to Fix Flaws: BIS

A BIS paper warns that AI is shortening the time banks have to repair...

US housing split: low-end sales down, luxury up on AI wealth

Compass CEO Robert Reffkin says U.S. housing market is splitting: low-end sales down 10%...

Trezor email partner breach exposes 347K users to phishing

Trezor's third-party email partner Brevo was breached, exposing 347,000 newsletter subscribers' email addresses.Hackers used...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading