Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

An unidentified French-speaking attacker compromised a small automotive business by deploying the Havoc C2 framework alongside a secondary persistence channel built from legitimate tools: OpenSSH and Tailscale VPN. When the primary command-and-control server was taken offline, the Tailscale/OpenSSH channel kept the attacker inside the network for 18 additional days, undetected. This case demonstrates that removing malware or disrupting C2 infrastructure is not sufficient for remediation when attackers embed themselves using trusted commercial software.

Author

Tech Jacks Solutions