Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions
ID: cd11f8ae-dc6b-54e1-92a5-13435d793448
STIX ID: report--cd11f8ae-dc6b-54e1-92a5-13435d793448
Feed Name: cybersecurityNews.com
Microsoft Incident Response investigated a stealthy, long‑running intrusion in which attackers abused the trusted HPE Operations Agent managed by a third‑party IT provider to deploy VBScripts and web shells (Errors.aspx, Signoff.aspx, ghost.inc), register malicious DLLs on domain controllers (mslogon.dll, passms.dll) to capture plaintext credentials, and exfiltrate data via SMB/email and ngrok tunnels; the report includes IoCs and remediation recommendations such as EDR deployment, outbound default‑deny, and monitoring for unexpected authentication configuration changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
