Executive Summary
In May 2026, Microsoft Incident Response investigated a sophisticated intrusion where threat actors exploited a compromised third-party IT services provider to gain access to an organization's network. Utilizing legitimate tools like HPE Operations Agent, the attackers executed scripts and binaries that mimicked routine administrative activities, enabling them to steal credentials and establish persistent access without detection. This method allowed the threat actors to move laterally across the network, compromising critical assets and maintaining a foothold over an extended period.
This incident underscores the growing trend of attackers leveraging trusted relationships and legitimate tools to infiltrate organizations, highlighting the need for enhanced monitoring and validation of third-party access and activities within enterprise environments.
Why This Matters Now
The increasing reliance on third-party service providers and management tools introduces significant security risks, as attackers exploit these trusted relationships to bypass traditional defenses. Organizations must implement stringent monitoring and validation processes to detect and prevent such stealthy intrusions.
Attack Path Analysis
The attacker gained initial access by compromising a third-party IT services provider and leveraging trusted management tools to execute scripts within the environment. They escalated privileges by deploying malicious components to intercept credentials during authentication processes. Using harvested credentials, the attacker moved laterally across critical systems, including domain controllers and SQL servers. They established command and control through encrypted tunnels, enabling remote access without detection. The attacker exfiltrated sensitive data by transferring it over covert channels. The impact included unauthorized access to sensitive information and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
The attacker gained initial access by compromising a third-party IT services provider and leveraging trusted management tools to execute scripts within the environment.
MITRE ATT&CK® Techniques
Trusted Relationship
Valid Accounts
Modify Authentication Process: Password Filter DLL
Server Software Component: Web Shell
Protocol Tunneling
Remote Services: Remote Desktop Protocol
Windows Management Instrumentation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and network security are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Third-party IT service providers face critical trust boundary vulnerabilities enabling stealthy intrusions through legitimate management tools and compromised authentication processes.
Health Care / Life Sciences
Healthcare organizations using third-party IT management face HIPAA compliance risks from encrypted traffic interception and lateral movement through trusted systems.
Financial Services
Financial institutions vulnerable to credential theft and data exfiltration through compromised third-party relationships bypassing traditional security controls and compliance frameworks.
Government Administration
Government entities face sophisticated nation-state attacks through trusted IT relationships enabling persistent access to sensitive infrastructure and classified systems.
Sources
- Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromisehttps://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise/Verified
- HPE Operations Agent Virtual Appliance, Local Escalation of Privilegehttps://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03722en_us&docLocale=en_USVerified
- HPE Operations Agent using OpenSSL, Remote Denial of Service (DoS), Unauthorized Access to Datahttps://support.microfocus.com/kb/kmdoc.php?id=KM02994337Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and data exfiltration by enforcing strict segmentation and identity-aware policies, thereby reducing the blast radius of the breach.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute scripts using trusted management tools may have been limited, reducing the scope of initial access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by intercepting credentials may have been constrained, reducing the risk of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across critical systems may have been restricted, reducing the potential spread of the breach.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish undetected command and control channels may have been limited, reducing the risk of persistent remote access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been constrained, reducing the risk of sensitive information loss.
The overall impact of unauthorized access and service disruption may have been reduced, limiting the extent of the breach.
Impact at a Glance
Affected Business Functions
- IT Infrastructure Management
- Network Security
- Identity and Access Management
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of administrative credentials and sensitive configuration data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities in real-time.
- • Establish Multicloud Visibility & Control to gain comprehensive insights into network traffic across all environments.
- • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.



