Operation Poisson – Analyzing a Cybercriminal’s Entire Operation

June 19, 2026, 11:39 a.m.

Description

A comprehensive analysis of 339 commands issued by a French-speaking threat actor nicknamed 'Poisson' over 33 days, targeting a French automotive small business and four French individuals. The attacker utilized a multi-stage fileless attack deploying a 70-line Python keylogger to harvest banking and email credentials. The operation leveraged free-tier infrastructure including Havoc C2 framework, Backblaze B2 storage, and DuckDNS. Most significantly, the attacker installed OpenSSH and Tailscale VPN on victim machines, creating persistent access that survived C2 server takedown. When the C2 went offline for 18 days, the attacker's access remained intact through the VPN mesh, demonstrating that VPN-mesh-based persistence is actively used in real-world intrusions and that traditional C2 takedown is insufficient for remediation.

Date

  • Created: June 19, 2026, 11:24 a.m.
  • Published: June 19, 2026, 11:24 a.m.
  • Modified: June 19, 2026, 11:39 a.m.

Indicators

  • f06e7e1a4363a01ba2a4fee2e28abdd623abf4194bda373f23ff0e151b5c2b45
  • 3b7642b0f84e83a36334c608655c6cb7aae774839a6a3488526b853d89830a60
  • 291cb1fd0f2709b4457447cbb87adacf5c36c1bcb0f8754524024d44174bb195
  • 0378a5ef51b008aa2d6b76bd44a0bf061339bc3b737a188ec82029444d4d18fe
  • 1f00fd604bb18bbe3081f9ce8d741c4029d2a2125eb8888ac4e0d955938059d6
  • aa7ea19e34567458b4ee66a7cd274181764984bf32123f756a7fdc64d5857b31
  • c79091ceae7cd592fc08e4854cda7c1182af762b6b126371cc604debdc995fc7
  • 217.154.162.45
  • 217.154.217.139

Attack Patterns

Additional Informations

  • Automotive
  • w456w5.s3.eu-central-003.backblazeb2.com
  • pois43.s3.eu-central-003.backblazeb2.com
  • wawsenti.duckdns.org
  • sentiwaw.s3.eu-central-003.backblazeb2.com
  • France