logo

Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks

ID: a8294278-af49-5d19-b235-988c1953d949

STIX ID: report--a8294278-af49-5d19-b235-988c1953d949

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Mayura Kathir

...
...

Microsoft disclosed a stealthy intrusion campaign where attackers, after compromising a third-party IT services provider, abused trusted enterprise management tools (HPE Operations Agent/Manager) to execute VBScript payloads and DLLs (notably 'mslogon' and 'passms.dll'), capture credentials on domain controllers and via LSA hooks, deploy web shells, and maintain covert remote access using ngrok and WMI-based execution; stolen credentials were encoded and exfiltrated, enabling prolonged lateral movement while blending into normal administrative workflows. Microsoft recommends EDR coverage, strict outbound controls, detailed logging, and adopting a zero-trust posture for third-party access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.