Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

An unidentified threat actor compromised a trusted third-party IT services provider and used that relationship to maintain undetected access to a target organization for 123 days. The attacker operated exclusively through legitimate HPE Operations Manager management tooling and abused Windows authentication mechanisms to harvest credentials in cleartext, enabling lateral movement to domain controllers. The business risk is severe: this attack exploited the implicit trust, privileged access, and monitoring gaps that third-party IT management relationships typically carry, meaning standard security controls may offer little visibility or resistance.

Author

Tech Jacks Solutions