VYPR
breachPublished Sep 29, 2026· 1 source

Storm-3068 Leverages Self-Service Password Reset for Azure DevOps and Kubernetes Compromise

Microsoft DART details how threat actor Storm-3068 exploited a self-service password reset to gain access to Azure DevOps, harvest Kubernetes credentials, and deploy remote access tools.

Microsoft's Detection and Response Team (DART) has investigated a sophisticated campaign by the threat actor Storm-3068, which successfully leveraged a compromised identity to infiltrate an organization's development and cloud environments. The intrusion began with Storm-3068 exploiting a self-service password reset process to gain initial access to a user account. Once control was established, the threat actor further secured their position by registering their own authentication methods, ensuring persistent access.

With a foothold secured, Storm-3068 shifted its focus to Azure DevOps, a critical platform at the nexus of identity, software development, and cloud operations. Instead of relying on traditional malware or software exploits, the threat actor employed legitimate administrative tools and custom scripts. This allowed them to meticulously enumerate repositories, projects, pipelines, and deployment environments, mapping out the organization's interconnected infrastructure.

The core of Storm-3068's strategy involved compromising trusted development pipelines. By modifying these pipelines, the threat actor aimed to harvest Kubernetes credentials and expand their reach into the organization's cloud infrastructure. This tactic highlights a growing trend where attackers exploit legitimate development workflows to achieve their objectives, making detection more challenging.

During the investigation, it was revealed that Storm-3068 created a malicious pipeline specifically designed to collect Kubernetes configuration files (kubeconfig) at scale. These files contain the necessary cluster connection details and authentication information. The threat actor deployed a kube agent and executed multiple jobs to harvest these sensitive credentials, leveraging the permissions of the initially compromised account to access over 50 resources.

Beyond credential harvesting, Storm-3068 also modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. These tools were deployed to establish alternative mechanisms for remote access and to expose the Kubernetes API server. Commands were executed to establish a reverse tunnel to an external IP address, potentially enabling direct remote interaction with targeted Kubernetes clusters.

Investigators pieced together the subsequent stages of the intrusion by analyzing Azure DevOps audit logs and Git version history. The threat actor successfully added seven stolen kubeconfig files to a repository, granting them the credentials required to access multiple Kubernetes clusters. This demonstrates how a single compromised identity can serve as a gateway to extensive cloud resources.

Microsoft DART worked closely with the affected customer to contain the intrusion and disrupt the threat actor's access. By analyzing telemetry across identity systems, development platforms, and cloud infrastructure, the team reconstructed the attack chain and identified the full extent of the compromise. DART provided prioritized guidance for containment and remediation, working side-by-side with the customer throughout the engagement.

This incident underscores the critical importance of securing the entire development and cloud ecosystem. Organizations are advised to monitor password reset activity for anomalies, strengthen protection for privileged accounts with phishing-resistant MFA, enforce strict code change approvals, control pipeline permissions, and apply least-privilege access principles across all resources to mitigate the impact of identity-driven attacks.

Synthesized by Vypr AI