logo

Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions

ID: cd11f8ae-dc6b-54e1-92a5-13435d793448

STIX ID: report--cd11f8ae-dc6b-54e1-92a5-13435d793448

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

Microsoft Incident Response investigated a stealthy, long‑running intrusion in which attackers abused the trusted HPE Operations Agent managed by a third‑party IT provider to deploy VBScripts and web shells (Errors.aspx, Signoff.aspx, ghost.inc), register malicious DLLs on domain controllers (mslogon.dll, passms.dll) to capture plaintext credentials, and exfiltrate data via SMB/email and ngrok tunnels; the report includes IoCs and remediation recommendations such as EDR deployment, outbound default‑deny, and monitoring for unexpected authentication configuration changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.