Unveiling the Junior Hacker's Move: How Tailscale and OpenSSH Kept Access Alive (2026)

The Persistence Playbook: How a Junior Hacker Outsmarted the System

In the world of cybersecurity, we often focus on the flashy exploits, the zero-days, and the advanced persistent threats (APTs). But what happens when a relatively inexperienced hacker manages to outmaneuver even seasoned professionals? That’s the story of 'Poisson,' a junior operator who broke into a small French automotive business and left behind a masterclass in persistence—a lesson that should make every security expert sit up and take notice.

The Unlikely Protagonist

Poisson, as described by Cato Networks researchers, is no APT. He’s a junior hacker, likely operating on a school schedule, using free-tier tools like DuckDNS, Backblaze B2, and a cheap IONOS VPS. His tradecraft is far from perfect—he leaked his home directory multiple times, named storage buckets after his own handle, and even left a test file of his keystrokes. Yet, despite these amateur mistakes, he compromised four machines and maintained access for weeks. What makes this particularly fascinating is how he achieved this: by thinking beyond the traditional command-and-control (C2) framework.

The Persistence Trick That Stole the Show

Here’s where Poisson’s story gets interesting. Before his C2 server went offline, he installed OpenSSH and Tailscale on the victim’s machine, effectively creating a backdoor that didn’t rely on his C2 infrastructure. When the Havoc server went dark, his access remained intact. This isn’t just clever—it’s a stark reminder that taking down a C2 server is often not enough. As Vitaly Simonovich of Cato CTRL points out, remediation efforts must go deeper, hunting for the quiet persistence layers that attackers leave behind.

Personally, I think this is a game-changer. It’s not about the sophistication of the tools but the mindset. Poisson used legitimate, signed binaries like Tailscale and OpenSSH, which are hard to detect if you’re only looking for malicious files. What this really suggests is that we need to shift our focus from file-based detection to behavior-based analysis. If you take a step back and think about it, this is a wake-up call for the entire industry.

The Broader Implications

Poisson’s tactics aren’t entirely new. APT groups like China’s APT31 and ransomware gangs like Akira have used similar tools to maintain stealthy access. But what’s striking here is that a junior hacker pulled it off. This raises a deeper question: if someone still learning can execute this level of persistence, how many other attackers are doing the same—and getting away with it?

One thing that immediately stands out is the reliance on legitimate tools. Tailscale, OpenSSH, RustDesk—these are all signed binaries that blend into normal network traffic. What many people don’t realize is that this makes them incredibly difficult to detect without behavioral analysis. For instance, why is OpenSSH installed on a Windows workstation? Why is Tailscale running on a machine with no need for a VPN? These are the questions security teams need to ask.

The Human Factor

What’s equally intriguing is the human element. Poisson’s operation was far from perfect. He failed at roughly half of what he tried, yet he still succeeded. This speaks to a larger trend in cybercrime: you don’t need to be a genius to cause significant damage. With the right tools and a bit of creativity, even a junior hacker can maintain access to sensitive systems for weeks.

A detail that I find especially interesting is the keylogger. Poisson didn’t exfiltrate data automatically; he logged in manually to grab the keystroke files. This manual approach is both low-tech and effective, and it highlights the importance of monitoring unusual login patterns. If a machine is suddenly staying awake for long periods (thanks to powercfg commands), that’s a red flag.

What’s Next?

Cato Networks provides a concrete hunting list, which is a great starting point. But the bigger lesson here is this: when you find a C2 server, assume it’s just one piece of the puzzle. The real threat lies in the persistence mechanisms that attackers leave behind. In my opinion, this is where the industry needs to focus its efforts—not just on takedowns, but on proactive hunting.

As for Poisson, his story ends with a mystery: what was in Thales.zip, and what did those two programs do in their 32 minutes on the machine? We may never know. But the takeaway is clear: the C2 server was never the intrusion itself—it was just one way in. And that’s the part remediation keeps missing.

Final Thoughts

Poisson’s operation is a reminder that cybersecurity isn’t just about technology; it’s about thinking like an attacker. Personally, I think this case will be studied for years to come, not because of its complexity, but because of its simplicity. It’s a wake-up call for all of us to look beyond the obvious and dig deeper. Because in the end, it’s not the tools that matter—it’s the mindset.

Unveiling the Junior Hacker's Move: How Tailscale and OpenSSH Kept Access Alive (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mr. See Jast

Last Updated:

Views: 6749

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.