iLOBleed is a persistent malicious implant targeting Hewlett Packard Enterprise iLO 4 baseboard management controller firmware on enterprise servers. It is widely characterized as a firmware-resident rootkit and has been associated with destructive intrusions in which compromised HPE servers were infected with wiper firmware that destroyed data on attached hard drives. Because it resides in the out-of-band management controller rather than the host operating system, iLOBleed can survive operating system reinstallation and hard-drive replacement while maintaining covert control below the OS layer.
The malware demonstrates the strategic value of BMC compromise for long-term persistence and post-exploitation on server infrastructure. A successful infection gives an attacker durable access to server management functions and a foothold that is difficult for defenders to detect or remediate using conventional endpoint controls. Documented cases indicate that iLOBleed was deployed on systems where a previously patched iLO vulnerability had not been remediated, underscoring its use against inadequately maintained management interfaces.
iLOBleed is notable as an early real-world example of destructive malware operating from server management firmware rather than from the host OS. Its targeting of HPE server infrastructure highlights the risk to enterprise and hosting environments that expose or insufficiently secure out-of-band management components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2013-4786 affecte le protocole IPMI 2.0 (introduit en 2004). Lors de l’échange RAKP, le BMC retourne un code HMAC-SHA1 calculé à partir du mot de passe du compte, accessible à un attaquant non authentifié pouvant joindre UDP port 623. Ce mécanisme permet une attaque par dictionnaire hors ligne sans générer de tentatives de connexion échouées sur le BMC cible.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious implant targeting HPE iLO/BMC environments that persists in firmware and wipes data on attached hard drives, surviving common remediation steps such as OS reinstallation or disk replacement.
Persistent iLO 4 rootkit/backdoor that can survive below the operating system in BMC firmware.
A rootkit deployed against HPE iLO servers, demonstrating that internet-exposed BMC/iLO interfaces can be abused for persistent compromise below the host operating system.
Firmware-resident rootkit targeting HPE iLO 4 management controllers, providing stealthy persistence below the operating system and associated with destructive server attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.