Hacker's Secret Backdoor: Tailscale and OpenSSH for Persistent Access (2026)

The Persistence Playbook: How a Junior Hacker Outsmarted the System

In the world of cybersecurity, we often focus on the flashy exploits, the zero-days, and the advanced persistent threats (APTs). But sometimes, it’s the simplest moves that catch us off guard. Take the case of 'Poisson,' a junior hacker who broke into a small French automotive business. What makes this particularly fascinating is not the sophistication of his tools, but the sheer ingenuity—and sloppiness—of his persistence strategy. Personally, I think this case is a masterclass in how attackers adapt, even when they’re still learning the ropes.

The Setup: A Tale of Amateur Tradecraft

Poisson’s operation was anything but stealthy. He used free-tier tools like DuckDNS, Backblaze B2, and a cheap IONOS VPS. His malware was memory-resident, relying on a VBScript stager and PowerShell loaders to deploy Havoc’s Demon agent. But here’s the kicker: he failed at roughly half of what he tried. He leaked his home directory multiple times, named his storage buckets after his own handle, and even left a test file of his keystrokes in the keylogger package. From my perspective, this is a classic case of a hacker who’s still figuring things out—but one who’s dangerously resourceful.

What many people don’t realize is that persistence is often the hardest part of an attack. Poisson’s keylogger grabbed banking and email credentials, but his real masterpiece was ensuring he could return even if his command-and-control (C2) server went offline. On April 7, he installed OpenSSH and Tailscale on the victim’s machine, creating a backdoor that didn’t rely on his C2. When the Havoc server went dark the next day, his access remained intact. This raises a deeper question: how often do we assume that taking down a C2 server means the threat is over? In this case, it was just the beginning.

The Move That Matters: Tailscale and OpenSSH

One thing that immediately stands out is Poisson’s use of Tailscale and OpenSSH. These tools are legitimate, signed binaries, which makes them nearly invisible to traditional detection methods. By joining the victim’s machine to his private Tailscale network and setting up a reverse SSH tunnel, he created a stealthy, encrypted pathway back into the system. If you take a step back and think about it, this is a brilliant—and terrifying—example of how attackers repurpose everyday tools for malicious ends.

What this really suggests is that we’re not just fighting malware; we’re fighting creativity. Poisson wasn’t using cutting-edge exploits or custom-built malware. He was leveraging tools that are freely available and widely used. A detail that I find especially interesting is how he kept the machine awake using powercfg, ensuring uninterrupted access to the keylogger data. It’s a small move, but it speaks volumes about his determination.

The Bigger Picture: Persistence Beyond the C2

The researchers at Cato Networks captured 339 commands over 33 days, providing a rare glimpse into an attacker’s thought process. But the real lesson here is about persistence. When the C2 server came back online 18 days later, Poisson’s agents reconnected automatically, and he resumed his activities as if nothing had happened. This isn’t just a technical failure—it’s a failure of mindset. We often treat the C2 as the heart of the intrusion, but what if it’s just one of many entry points?

From my perspective, this case highlights a critical blind spot in remediation strategies. Taking down a C2 server is a reactive measure, but it’s not enough. Attackers like Poisson are building redundant pathways, ensuring they can return even if their primary infrastructure is compromised. This isn’t just about technical defenses; it’s about thinking like an attacker. What if, instead of focusing solely on the C2, we hunted for the quiet persistence layers lurking in the shadows?

What to Watch For: Beyond the Obvious

Cato’s hunting list is a great starting point, but it’s just the tip of the iceberg. Alerting on OpenSSH installations on Windows workstations, monitoring for tailscale.exe on machines without a legitimate need, and flagging reverse SSH tunnels are all solid recommendations. But here’s the thing: these indicators are reactive. They tell us what’s already happened, not what’s coming next.

In my opinion, the real challenge is detecting anomalous behavior before it becomes a full-blown intrusion. Why was Poisson able to install OpenSSH and Tailscale in the first place? Why didn’t the victim’s security tools flag the reverse tunnel? These are questions we need to ask ourselves. Personally, I think we need to shift from a file-based detection model to a behavior-based one. It’s not about the binaries; it’s about the intent behind them.

The Unanswered Question: Thales.zip

One of the most intriguing aspects of this case is the mysterious Thales.zip file. Poisson ran two executables from it for 32 minutes before deleting 17 files and going quiet. What were those programs doing? Were they probing for further vulnerabilities, exfiltrating data, or something else entirely? Cato leaves this question open, but it’s a reminder that even junior hackers can leave behind puzzles we’re not equipped to solve.

What this really suggests is that we’re often one step behind. Poisson’s operation was far from perfect, yet he managed to compromise four machines and maintain access for weeks. If a junior hacker can pull this off, imagine what a more experienced operator could do. This isn’t just a cautionary tale—it’s a call to action.

Final Thoughts: The Persistence Paradox

As I reflect on Poisson’s operation, one thing is clear: persistence is the new frontier in cybersecurity. We can’t afford to focus solely on the initial intrusion or the C2 server. We need to think like attackers, hunting for the quiet backdoors and redundant pathways they leave behind. What makes this case so compelling is its simplicity. Poisson didn’t need advanced tools or techniques—he just needed creativity and determination.

In my opinion, this is a wake-up call for the industry. We need to rethink our remediation strategies, focusing not just on what we can see, but on what we can’t. The C2 server is just one piece of the puzzle. The real threat lies in the persistence mechanisms that allow attackers to return, again and again. As we move forward, let’s not just react to threats—let’s anticipate them. Because in the world of cybersecurity, the only constant is change.

Hacker's Secret Backdoor: Tailscale and OpenSSH for Persistent Access (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Twana Towne Ret

Last Updated:

Views: 6053

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Twana Towne Ret

Birthday: 1994-03-19

Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

Phone: +5958753152963

Job: National Specialist

Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.