Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors poisson

Also known as: tracked as, a Poisson random measure, monkeypox, a Poisson point field

Description

A comprehensive analysis of 339 commands issued by a French-speaking threat actor nicknamed 'Poisson' over 33 days, targeting a French automotive small business and four French individuals. The attacker utilized a multi-stage fileless attack deploying a 70-line Python keylogger to harvest banking and email credentials. The operation leveraged free-tier infrastructure including Havoc C2 framework, Backblaze B2 storage, and DuckDNS. Most significantly, the attacker installed OpenSSH and Tailscale VPN on victim machines, creating persistent access that survived C2 server takedown. When the C2 went offline for 18 days, the attacker's access remained intact through the VPN mesh, demonstrating that VPN-mesh-based persistence is actively used in real-world intrusions and that traditional C2 takedown is insufficient for remediation.

Goals & Targeting

Targeted Sectors

Financial services
Non profit
Healthcare
Manufacturing
Education
Government

Targeted Countries / Regions

France
GB
FR

AI Analysis

· 2 weeks ago

Executive Summary

The Poisson threat actor is a French-speaking entity that has been observed targeting French automotive small businesses and individuals, utilizing a multi-stage fileless attack to harvest banking and email credentials. The actor leverages free-tier infrastructure and creates persistent access through the installation of OpenSSH and Tailscale VPN on victim machines. This persistence allows the actor to maintain access even after the C2 server is taken down.

Goals & Targeting

The Poisson threat actor's strategic objectives appear to be focused on harvesting sensitive information, such as banking and email credentials, from French-speaking organizations and individuals. The actor's targeting of automotive small businesses and individuals suggests a potential interest in the French economy or industry. The actor's use of VPN-mesh-based persistence and multi-stage fileless attacks indicates a high degree of sophistication and a desire to maintain long-term access to compromised networks.

Enhanced Description

The Poisson threat actor is a sophisticated entity that has been observed conducting targeted attacks against French-speaking organizations and individuals. The actor's modus operandi involves the use of a multi-stage fileless attack, which begins with the deployment of a 70-line Python keylogger designed to harvest sensitive information such as banking and email credentials. The attack leverages free-tier infrastructure, including the Havoc C2 framework, Backblaze B2 storage, and DuckDNS, to establish command and control (C2) capabilities. Notably, the actor installs OpenSSH and Tailscale VPN on compromised machines, creating a persistent access mechanism that enables the actor to maintain a foothold in the victim's network even after the C2 server is taken offline. This tactic, known as VPN-mesh-based persistence, allows the actor to continue conducting malicious activities without relying on a traditional C2 infrastructure.

Key Capabilities

  • Multi-stage fileless attacks
  • Python keylogger development
  • Free-tier infrastructure utilization
  • OpenSSH and Tailscale VPN installation
  • VPN-mesh-based persistence

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1071.001

Software / Tooling

Havoc C2 framework
Backblaze B2 storage
DuckDNS
Tailscale VPN
OpenSSH

Campaigns & Victims

The Poisson actor's campaign patterns suggest a high degree of planning and sophistication. The actor's use of multi-stage fileless attacks and VPN-mesh-based persistence indicates a desire to maintain long-term access to compromised networks. The actor's targeting of French-speaking organizations and individuals suggests a specific geographic focus, potentially indicating a regional or linguistically-based motivation. Notable past operations include the compromise of a French automotive small business and four French individuals, highlighting the actor's ability to target and compromise multiple organizations and individuals.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on free-tier cloud services

Recommended Actions

  • Implement robust network segmentation and access controls
  • Utilize endpoint detection and response (EDR) tools
  • Conduct regular security audits and vulnerability assessments
  • Develop incident response plans to address VPN-mesh-based persistence

Suggested Tags

APT
fileless malware
VPN-mesh-based persistence

Confidence Assessment

The available data provides a high degree of confidence in the Poisson actor's tactics, techniques, and procedures (TTPs). However, there are information gaps regarding the actor's primary motivations and goals, as well as the scope of their operations. Further analysis is needed to determine the actor's full range of capabilities and targeting preferences.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: monkeypox
  2. www.fortinet.com — Cited by web research for: phishing
  3. support.microsoft.com — Cited by web research for: Microsoft Teams
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: Unknown

Intel Summary

0

Techniques

30

Tools

0

Campaigns

44

IOCs

0

Observed Data

0

Tactics

Tags

APT
Financial Targeting
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 19, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.