logo

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

ID: 3239eb94-926a-5afd-a401-f7b536d3a89f

STIX ID: report--3239eb94-926a-5afd-a401-f7b536d3a89f

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Microsoft Incident Response

...
...

Microsoft investigated a sophisticated intrusion where attackers leveraged a compromised third-party IT services provider and legitimate HPE Operations Manager/Agent tooling to execute VBScripts and web shells, register malicious authentication components (mslogon.dll, passms.dll) on domain controllers to harvest credentials, and deploy tunneling (ngrok) for covert RDP and lateral movement; the report describes the attack timeline, TTPs, detection/hunting queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.