Also known as: tracked as, a Poisson random measure, monkeypox, a Poisson point field
A comprehensive analysis of 339 commands issued by a French-speaking threat actor nicknamed 'Poisson' over 33 days, targeting a French automotive small business and four French individuals. The attacker utilized a multi-stage fileless attack deploying a 70-line Python keylogger to harvest banking and email credentials. The operation leveraged free-tier infrastructure including Havoc C2 framework, Backblaze B2 storage, and DuckDNS. Most significantly, the attacker installed OpenSSH and Tailscale VPN on victim machines, creating persistent access that survived C2 server takedown. When the C2 went offline for 18 days, the attacker's access remained intact through the VPN mesh, demonstrating that VPN-mesh-based persistence is actively used in real-world intrusions and that traditional C2 takedown is insufficient for remediation.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Poisson threat actor is a French-speaking entity that has been observed targeting French automotive small businesses and individuals, utilizing a multi-stage fileless attack to harvest banking and email credentials. The actor leverages free-tier infrastructure and creates persistent access through the installation of OpenSSH and Tailscale VPN on victim machines. This persistence allows the actor to maintain access even after the C2 server is taken down.
Goals & Targeting
The Poisson threat actor's strategic objectives appear to be focused on harvesting sensitive information, such as banking and email credentials, from French-speaking organizations and individuals. The actor's targeting of automotive small businesses and individuals suggests a potential interest in the French economy or industry. The actor's use of VPN-mesh-based persistence and multi-stage fileless attacks indicates a high degree of sophistication and a desire to maintain long-term access to compromised networks.
Enhanced Description
The Poisson threat actor is a sophisticated entity that has been observed conducting targeted attacks against French-speaking organizations and individuals. The actor's modus operandi involves the use of a multi-stage fileless attack, which begins with the deployment of a 70-line Python keylogger designed to harvest sensitive information such as banking and email credentials. The attack leverages free-tier infrastructure, including the Havoc C2 framework, Backblaze B2 storage, and DuckDNS, to establish command and control (C2) capabilities. Notably, the actor installs OpenSSH and Tailscale VPN on compromised machines, creating a persistent access mechanism that enables the actor to maintain a foothold in the victim's network even after the C2 server is taken offline. This tactic, known as VPN-mesh-based persistence, allows the actor to continue conducting malicious activities without relying on a traditional C2 infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Poisson actor's campaign patterns suggest a high degree of planning and sophistication. The actor's use of multi-stage fileless attacks and VPN-mesh-based persistence indicates a desire to maintain long-term access to compromised networks. The actor's targeting of French-speaking organizations and individuals suggests a specific geographic focus, potentially indicating a regional or linguistically-based motivation. Notable past operations include the compromise of a French automotive small business and four French individuals, highlighting the actor's ability to target and compromise multiple organizations and individuals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a high degree of confidence in the Poisson actor's tactics, techniques, and procedures (TTPs). However, there are information gaps regarding the actor's primary motivations and goals, as well as the scope of their operations. Further analysis is needed to determine the actor's full range of capabilities and targeting preferences.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
30
Tools
0
Campaigns
44
IOCs
0
Observed Data
0
Tactics