Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks
ID: a8294278-af49-5d19-b235-988c1953d949
STIX ID: report--a8294278-af49-5d19-b235-988c1953d949
Feed Name: GBHackers
Microsoft disclosed a stealthy intrusion campaign where attackers, after compromising a third-party IT services provider, abused trusted enterprise management tools (HPE Operations Agent/Manager) to execute VBScript payloads and DLLs (notably 'mslogon' and 'passms.dll'), capture credentials on domain controllers and via LSA hooks, deploy web shells, and maintain covert remote access using ngrok and WMI-based execution; stolen credentials were encoded and exfiltrated, enabling prolonged lateral movement while blending into normal administrative workflows. Microsoft recommends EDR coverage, strict outbound controls, detailed logging, and adopting a zero-trust posture for third-party access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
