Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-12 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

The stealthy intrusion was a signed HPE agent under a third-party IT contract, not a 0-day

Microsoft Incident Response found long-term access, credential theft, and persistence delivered through a legitimate HPE Operations Agent that a provider already had rights to run.

RWP Ventures · 2026-09-07 · event 2026-05-12 · 2 min read · priority 8.4

Bottom line up front

CONFIRMED Microsoft's 12 May 2026 IR write-up describes an intrusion that looked like routine administration. The delivery mechanism was HPE Operations Agent (OA), an approved, signed enterprise management tool. Microsoft is explicit: no vulnerability in HPE OA. Management of that platform had been delegated to a third-party IT services provider, so the trust boundary was the contract, not the binary. The actor used that path for durable access, credential theft, and a persistent foothold.

Do not flatten this into "HPE was hacked" or into Storm-1175. Adjacent sources below are about why signed admin tooling is a preferred living-off-the-land path in ransomware too — not attribution of this IR case.

Historical backfill of 12 May 2026 reporting; added 7 September 2026.

What happened

A provider already allowed to push OA did so. Telemetry that treats signed management agents as trusted will not fire. The investigation had to reconstruct intent from operational relationships, not from malware families.

Why it mattered

Every org that outsources monitoring has this shape. Privileged access management for vendors is the control; EDR allow-lists for "known good vendors" are the hole.

OT: UNKNOWN. An OA-class agent on a historian jump box would be a process-impact path if it existed; Microsoft did not claim OT.

Who / what was affected

The IR customer is not named. Pattern applies to any enterprise that delegated OA (or SCCM, Intune partner, RMM) to a third party.

Technical context

Inventory who can deploy signed agents. Conditional access and PAM for vendor identities. Alert on new local admins and unexpected scheduled tasks originating from management agents.

Exploitation / threat status at the time

CONFIRMED Microsoft IR facts as stated.

UNKNOWN actor name and victim identity.

What defenders should have done

  1. Treat MSP/RMM identities as tier-0.
  2. Do not equate Authenticode with intent.
  3. Tabletop "our monitoring vendor is the attacker."

RWP assessment

Confidence: High on the IR pattern. Low on public victim/actor IDs because Microsoft withheld them.

Defensive actions

  1. Vendor PAM with just-in-time, recorded sessions.
  2. Allow-list which hosts may run OA.
  3. Hunt credential dumps after any vendor-agent anomaly.

Sources

  1. Microsoft Incident Response — Undermining the trust boundary: third-party compromise
  2. Microsoft — Storm-1175 web-facing Medusa operations (adjacent trusted-admin pattern)
  3. CISA — #StopRansomware: Medusa Ransomware