{"id":1173,"date":"2026-08-20T11:07:43","date_gmt":"2026-08-20T05:37:43","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1173"},"modified":"2026-08-20T11:09:42","modified_gmt":"2026-08-20T05:39:42","slug":"tailscale-openssh-persistence-after-c2-outage","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/","title":{"rendered":"Tailscale Persistence &#038; OpenSSH Maintain Access After C2 Outage"},"content":{"rendered":"<p>A recent Cato Networks investigation highlights a challenge many security teams continue to underestimate: removing malware infrastructure does not necessarily remove attacker access. The case also demonstrates how Tailscale persistence can help attackers maintain connectivity even after their primary command-and-control infrastructure is disrupted.<\/p>\n<p>In the reported intrusion, the attacker maintained access to the environment even after their primary command-and-control (C2) channel became unavailable. Instead of relying solely on custom malware, they established alternative access paths using legitimate remote administration technologies, allowing persistence beyond the lifespan of the original attack infrastructure.<\/p>\n<p>For enterprise defenders, this reinforces an important reality. Modern incident response cannot stop at disrupting malware communications or blocking known indicators of compromise. Security teams must also identify and eliminate unauthorized remote access mechanisms, persistence techniques, and trusted administrative tools that attackers may have deployed to survive remediation efforts.<\/p>\n<p>The incident serves as a reminder that attackers do not always need sophisticated malware to remain inside a network. In many cases, legitimate tools and services can provide a more resilient and less conspicuous foothold than traditional command-and-control frameworks.<\/p>\n<h2>Breaking Down the Multi-Stage Intrusion<\/h2>\n<p>The attack followed a multi-stage execution chain designed to minimize detection and maintain flexibility throughout the intrusion. According to Cato Networks&#8217; analysis, the infection began with a VBScript-based stager that launched PowerShell components, which then delivered a .NET loader responsible for deploying the Havoc Demon implant. Much of the malicious activity operated in memory, reducing the forensic artifacts typically associated with disk-based malware.<\/p>\n<p>Once execution was established, the attacker focused on persistence and privilege escalation. The investigation observed attempts to elevate privileges using Windows&#8217; <code>Start-Process -Verb RunAs<\/code> functionality, followed by the creation of scheduled tasks configured to run with the highest available privileges at user logon.<\/p>\n<p>Additional persistence and evasion mechanisms included:<\/p>\n<ul>\n<li>Shellcode injection into Explorer.exe to blend malicious activity with a trusted Windows process.<\/li>\n<li>Deployment of a keylogger to capture credentials and user activity.<\/li>\n<li>Installation of a custom RustDesk instance as an alternative remote-access channel.<\/li>\n<li>Use of multiple execution layers to complicate detection and remediation efforts.<\/li>\n<\/ul>\n<p>The most significant aspect of the intrusion emerged after the primary malware infrastructure became unavailable. Before the Havoc command-and-control environment went offline, the attacker installed OpenSSH Server and Tailscale on the compromised Windows system.<\/p>\n<p>By connecting the endpoint to a private Tailscale network, enabling SSH key-based authentication, and configuring a reverse SSH tunnel, the attacker established an independent access path that no longer relied on the original command-and-control framework. This form of Tailscale persistence allowed access to survive even after the Havoc infrastructure became unavailable.<\/p>\n<p>From a defensive perspective, this transition is particularly noteworthy because both OpenSSH and Tailscale are legitimate tools widely used for IT administration. Without visibility into process lineage, persistence mechanisms, and configuration changes, these installations can appear legitimate. As a result, distinguishing them from authorized administrative activity becomes more difficult.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief-.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-IdP-Solution-brief\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief-.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief--300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief--768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief--133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-IdP-Solution-brief\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode IdP Solution Brief\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Check out this solution brief for a quick glance into Hexnode IdP's capabilities.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/datasheets\/hexnode-idp-solution-brief\/'>\n                            Get the Datasheet\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode Helps Detect and Respond to Similar Threats<\/h2>\n<p>Incidents like this highlight the need for security controls that extend beyond malware detection. Once attackers begin leveraging legitimate administrative tools such as Tailscale, OpenSSH, or RustDesk, organizations need visibility into endpoint activity, persistence mechanisms, and unauthorized software deployments rather than relying solely on traditional threat indicators.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> can help security teams investigate and respond to suspicious activity across managed endpoints by providing endpoint visibility, threat investigation capabilities, and response actions such as device isolation when malicious behavior is identified. This becomes particularly valuable when investigating attacks that involve script-based execution, privilege escalation attempts, unauthorized remote-access software, or persistence mechanisms.<\/p>\n<p>From a device management perspective, <a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> helps organizations reduce exposure by enforcing application governance and compliance policies across endpoints. IT teams can:<\/p>\n<ul>\n<li>Monitor devices for the presence of unauthorized or unapproved applications.<\/li>\n<li>Establish application allowlists and blocklists as part of compliance policies.<\/li>\n<li>Maintain endpoint compliance across Windows environments.<\/li>\n<li>Execute remote management and remediation actions on managed devices when suspicious activity is discovered.<\/li>\n<\/ul>\n<p>Together, endpoint management and security visibility help organizations identify potentially unauthorized remote-access tools, investigate suspicious changes on affected systems, and accelerate remediation before attackers can establish long-term persistence.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/10-Signs-of-a-Poor-Digital-Employee-Experience.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Signs Your Organization Has a Poor Digital Employee Experience (And What to Do About It)<\/h4><p>Discover the 10 warning signs of poor digital employee experience and how proactive IT can eliminate the friction.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/signs-of-poor-digital-employee-experience\/\" aria-label=\"Top 10 Signs Your Organization Has a Poor Digital Employee Experience (And What to Do About It)\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Conclusion<\/h2>\n<p>This incident demonstrates a critical lesson for security and IT operations teams: disrupting command-and-control infrastructure is not the same as fully remediating a compromised endpoint.<\/p>\n<p>The attacker did not rely exclusively on malware to maintain access. By deploying legitimate remote administration technologies and establishing alternative access channels, they created persistence mechanisms capable of surviving the loss of their primary command-and-control environment. For defenders, this means incident response efforts must extend beyond blocking malicious domains, removing malware, or terminating active sessions.<\/p>\n<p>Effective remediation requires a combination of:<\/p>\n<ul>\n<li>Endpoint telemetry to uncover suspicious process activity and configuration changes.<\/li>\n<li>Tool governance to identify and control unauthorized remote-access software.<\/li>\n<li>Persistence hunting to detect scheduled tasks, remote access services, credential-based access paths, and other long-term footholds.<\/li>\n<li>Device isolation and response capabilities to contain compromised systems before attackers can re-establish access.<\/li>\n<\/ul>\n<p>As attackers increasingly blend legitimate administrative tools with traditional malware techniques, organizations need visibility into both malicious and seemingly legitimate activity. Cases involving Tailscale persistence illustrate why security teams must investigate legitimate remote-access tools with the same rigor applied to traditional malware artifacts.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f <\/h5><p>Gain visibility into endpoint activity and respond faster to emerging security threats with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent Cato Networks investigation highlights a challenge many security teams continue to underestimate: removing&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1175,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,20],"class_list":["post-1173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-windows","category-network-and-vpn","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Tailscale Persistence &amp; OpenSSH Maintain Access After C2 Outage<\/title>\n<meta name=\"description\" content=\"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Tailscale Persistence &amp; OpenSSH Maintain Access After C2 Outage\" \/>\n<meta property=\"og:description\" content=\"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T05:37:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T05:39:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Tailscale Persistence &#038; OpenSSH Maintain Access After C2 Outage\",\"datePublished\":\"2026-08-20T05:37:43+00:00\",\"dateModified\":\"2026-08-20T05:39:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/\"},\"wordCount\":865,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Tailscale-persistence.webp?format=webp\",\"articleSection\":[\"Windows\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/\",\"name\":\"Tailscale Persistence & OpenSSH Maintain Access After C2 Outage\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Tailscale-persistence.webp?format=webp\",\"datePublished\":\"2026-08-20T05:37:43+00:00\",\"dateModified\":\"2026-08-20T05:39:42+00:00\",\"description\":\"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Tailscale-persistence.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Tailscale-persistence.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"Tailscale-persistence\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/tailscale-openssh-persistence-after-c2-outage\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tailscale Persistence &#038; OpenSSH Maintain Access After C2 Outage\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Tailscale Persistence & OpenSSH Maintain Access After C2 Outage","description":"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/","og_locale":"en_US","og_type":"article","og_title":"Tailscale Persistence & OpenSSH Maintain Access After C2 Outage","og_description":"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-20T05:37:43+00:00","article_modified_time":"2026-08-20T05:39:42+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Tailscale Persistence &#038; OpenSSH Maintain Access After C2 Outage","datePublished":"2026-08-20T05:37:43+00:00","dateModified":"2026-08-20T05:39:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/"},"wordCount":865,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp","articleSection":["Windows","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/","url":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/","name":"Tailscale Persistence & OpenSSH Maintain Access After C2 Outage","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp","datePublished":"2026-08-20T05:37:43+00:00","dateModified":"2026-08-20T05:39:42+00:00","description":"Learn how attackers use Tailscale persistence and OpenSSH to maintain access even after C2 infrastructure is disrupted.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Tailscale-persistence.webp?format=webp","width":1024,"height":535,"caption":"Tailscale-persistence"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/tailscale-openssh-persistence-after-c2-outage\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Tailscale Persistence &#038; OpenSSH Maintain Access After C2 Outage"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1173"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1173\/revisions"}],"predecessor-version":[{"id":1181,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1173\/revisions\/1181"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1175"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}