Utopia Tech
SecurityAI-assisted1 min read

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

A French-speaking threat actor compromised a small automotive business using credential theft and keylogging, but distinguished himself by installing OpenSSH and Tailscale as persistent backdoors independent of his command-and-control infrastructure. This tactic ensured continued access even after his Havoc C2 server went offline, demonstrating evolving attacker resilience strategies that bypass t

UT

Utopia Tech

June 17, 2026 · 1 min read

Share

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a way back in that did not run through the C2 at all. When the Havoc server went offline the next

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content