HomeSecurityYoung hacker used Tailscale and OpenSSH to hack into French automotive company

Young hacker used Tailscale and OpenSSH to break into French car manufacturer

A French-speaking hacker broke into a small French car manufacturer, installed a keylogger, and stole email credentials. Before his command and control (C2) server went down, he installed OpenSSH and Tailscale on a victim's computer, creating a backdoor that bypassed the C2 at all. When the Havoc server went down the next day, his access was not interrupted.

See also: OpenSSH regreSSHion RCE bug gives root access to Linux servers

OpenSSH

Eighteen days later, the C2 was back up, its agents automatically reconnected, and it continued its operations. Cato Networks documented the entire operation command-by-command, a total of 339 commands over 33 days, after the operator left his SSH keys and a step-by-step guide in an open storage bin. The analysis, published by Cato CTRL Vitaly Simonovich, provides a rare glimpse into an intrusion from the operator’s perspective, rather than the forensic remains.

The researchers’ lesson is clear: taking down a C2 server is not a sufficient remedy if the attacker has already established a separate access point. The attacker, known as “Poisson,” is not classified as an advanced persistent threat (APT). The researchers describe him as a young operator with a student-like schedule, active after 3 p.m. CET with a long lunch break, using free resources like DuckDNS, Backblaze B2 , and a cheap IONOS VPS in Berlin.

His techniques were inadequate. He leaked his home directory multiple times, named his storage bins with his own alias, and left a test file of his keystrokes repeatedly inside the keylogger package. Despite failing about half of his attempts, he managed to compromise four computers. The malware ran almost entirely in memory. A VBScript with sandbox-evasion latency decrypted a PowerShell loader, which downloaded a .NET loader that ran Havoc's Demon agent without writing the implant to disk.

To elevate, it used Start-Process -Verb RunAs, which triggers the Windows consent dialog and requires user interaction. On one victim, it took twelve attempts over two days. It then created a scheduled task that runs on every login with the highest privileges, injected shellcode into Explorer.exe , and created a custom RustDesk as a fallback channel.

See also: OpenSSH flaws expose SSH servers to MiTM and DoS attacks

Young hacker used Tailscale and OpenSSH to break into French car manufacturer

The credential collector was a 70-line Python keylogger that logged keystrokes to a local file, with no beacon and no export server. Poisson manually connected, retrieved the file, and used powercfg to prevent the computers from going dormant, ensuring continuous data collection. On April 7, during a five-hour overnight session, he installed OpenSSH Server and Tailscale, connected the victim's computer to his Tailscale private network, and set up key-based SSH and a reverse tunnel.

This allowed him to access the computer through Tailscale’s encrypted mesh without C2 and without any exposed ports. The next day, the Havoc infrastructure went down. Cato doesn’t elaborate on why, but it’s largely irrelevant: the Tailscale route was running on a separate network, so access remained intact. When C2 returned on April 26, the agents reconnected automatically, without requiring a re-breach.

Over the past five days, it executed 145 additional commands, probed smart card and certificate stores (indicating that it was interested in certificate-based connections), ran two inexplicable executables from a file named Thales.zip for about 32 minutes, then deleted 17 files and ceased activity on May 1. Its goals were narrow.

There was no use of Mimikatz, no side-stepping, no ransomware, and no indication that it extracted the documents it accessed, which included tax records and insurance information. It focused solely on what people typed in: banking logins, email passwords, and government portal credentials. For a small business owner, this represents significant financial risk.

None of the tools used were new, which is important. China's APT31 used Tailscale in 2024 and 2025 to silently bypass Russian IT companies, while Scattered Spider has relied on legitimate remote access tools like Ngrok and Fleetdeck.

See also: 🏆 WINNERS 🏆Giveaway – Cybersecurity 101: Fundamentals for Junior Engineers and Job Seekers

GopherWhisper Chinese APT group malware attacks Discord Slack

RustDesk, Poisson's backup channel, has also been seen in recent Akira ransomware attacks. The binaries used were signed and legitimate, meaning that detection methods that focus solely on identifying malicious files, rather than monitoring suspicious behavior, will likely miss them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS