Find notable cyber news and cases, enriched with sources, timelines, and signals.

Small French automotive business hit by network compromise

Incident
First reported
Last updated
Happening score
H score 4
1 unique sources, 1 articles

Summary

Hide ▲

The small French automotive business suffered a credential-theft intrusion that exposed banking and email access and preserved attacker persistence after the primary C2 went offline. The attacker also installed OpenSSH Server and Tailscale on April 7 to keep a separate way back in. When the Havoc server returned on April 26, the agent reconnected automatically and the activity continued through May 1.

Timeline

  1. 17.06.2026 19:00 1 articles · 4h ago

    Poisson installs OpenSSH Server and Tailscale for alternate access

    Technical Analysis Update

    On April 7, Poisson installed OpenSSH Server and Tailscale on the victim's machine, joined it to a private Tailscale network, and set up key-based SSH plus a reverse tunnel so he could keep reaching the affected French automotive business without relying on Havoc.

    Show sources
  2. 17.06.2026 19:00 2 articles · 4h ago

    Cato CTRL discloses the Poisson intrusion into a small French automotive business

    Initial Disclosure

    On June 17, 2026, Cato CTRL disclosed Poisson's intrusion into a small French automotive business, describing a keylogger, stolen banking and email credentials, and the separate OpenSSH Server and Tailscale persistence path after the Havoc C2 went offline.

    Show sources