threat-intel
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
Medium
Summary
A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH and Tailscale to create a secure, C2-free channel, allowing him to continue operations undetected for over 30 days. The incident highlights the importance of identifying and mitigating alternative access methods beyond simply disabling a compromised C2 server, emphasizing the need for proactive monitoring and detection of persistent access techniques.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
