Beyond source code: A path to the keys to the kingdom
Storm-3068 exploited compromised identity to gain cloud access via Azure DevOps and Kubernetes.
Summary
Threat actor Storm-3068 leveraged a compromised user identity, initially gained through a self-service password reset, to access Azure DevOps and Kubernetes resources. The group exploited trusted development pipelines to harvest credentials and establish persistent access to cloud infrastructure, bypassing traditional malware-based attacks. Microsoft's DART team investigated and disrupted the actor's activities.
Full text
Share Link copied to clipboard! Content typesBest practicesProducts and servicesMicrosoft Defender ExpertsMicrosoft Defender Experts Cybersecurity Incident ResponseTopicsCloud securityIncident responseSecurity managementThreat trends What began as a single compromised identity quickly expanded into an organization’s development and cloud environments. In our latest Cyberattack Series report, we examine how the Microsoft Detection and Response Team (DART)—the team that delivers Microsoft Defender Experts Cybersecurity Incident Response—investigated activity by Storm-3068, a threat actor that turned a successful self-service password reset into access to Azure DevOps, development pipelines, and Kubernetes resources. By leveraging legitimate identity and cloud services rather than malware or software exploits, the threat actor established persistent access, enumerated repositories, and obtained credentials that opened a path into connected cloud infrastructure. This case highlights a growing challenge for defenders: when identities, source code, pipelines, and production environments are tightly linked, a single account compromise can provide a pathway to much broader access across the organization. Read on to learn more or access the full report. Read the full cyberattack report What happened? The intrusion began with Storm-3068 gaining access to a user account through a self-service password reset process and then taking full control of the identity by registering its own authentication methods. With persistent access established, the threat actor shifted its focus to Azure DevOps using legitimate administrative tools and automated scripts to enumerate repositories, projects, pipelines, and deployment environments. TACTIC: Trusted pipelines were exploitedRather than deploying malware, the threat actor modified development pipelines to collect Kubernetes credentials and expand access into cloud infrastructure. Azure DevOps proved to be a high-value target because it sat at the intersection of identity, software development, and cloud operations. By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise. The investigation revealed that Storm-3068 created a malicious pipeline designed to harvest Kubernetes credentials at scale. The pipeline deployed a kube agent and executed multiple jobs intended to collect kubeconfig files containing cluster connection details and authentication information. Leveraging the permissions of the compromised account, the threat actor deployed the pipeline that was authorized to access more than 50 resources and authenticated to services. In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. These tools were deployed in an attempt to provide the threat actor with alternative mechanisms for remote access and to expose the Kubernetes API server. Chisel commands were executed to establish a reverse tunnel to an external IP address to enable potential remote interaction with the Kubernetes clusters. Using Azure DevOps audit logs and Git version history, investigators reconstructed the next stage of the intrusion. The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters. INSIGHT: Azure DevOps can reveal much more than source codeRepositories, pipelines, service connections, and deployment settings can provide threat actors with a roadmap to an organization’s broader environment. How did Microsoft respond? Once engaged, DART moved quickly to investigate the intrusion and disrupt the threat actor’s access. By analyzing telemetry across identity systems, development platforms, and cloud infrastructure, the team pieced together how the cyberattack unfolded and identified where the threat actor had expanded beyond the initial compromise. Throughout the engagement, DART worked side by side with the customer, sharing findings through daily briefings and providing prioritized guidance to support containment and remediation efforts. As new details emerged, this close coordination helped the customer make informed decisions and respond quickly. DART also collaborated with Microsoft Threat Intelligence to place the activity in a broader threat context, helping refine the investigation and focus response efforts across affected environments. Beyond containing the intrusion, DART provided recommendations to help improve resilience and reduce opportunities for future compromise. Read the full report to learn how the investigation uncovered the extent of the threat actor’s access and the key lessons organizations can apply to defend against similar identity-driven attacks. Learn more about Microsoft Defender Experts Cybersecurity Incident Response What can customers do to strengthen their defenses? While the attack began with a compromised identity, its impact grew as the threat actor moved through development and cloud environments. Organizations can reduce similar risks by focusing on: Monitoring password reset activity for unusual patterns, including repeated reset attempts or activity targeting multiple users. Strengthening protection for privileged accounts by limiting exposure to self-service password reset workflows and requiring phishing-resistant multifactor authentication. Requiring approvals for code changes and enforcing branch protection policies to prevent unauthorized modifications. Restricting direct commits to critical branches so changes follow established review and approval processes. Controlling pipeline permissions and limiting who can create, modify, or execute build and deployment pipelines. Applying least-privilege access principles across identities, development platforms, and cloud resources to minimize the impact of a compromised account. INSIGHT: Identities are the new attack pathThis incident demonstrates how a single compromised identity can provide access to development platforms, cloud resources, and production environments when those systems are tightly connected. As this case demonstrates, a single compromised identity can become a pathway to much broader access when development platforms, deployment pipelines, and cloud infrastructure are tightly connected. Regular reviews of identity, DevOps, and cloud security controls can help reduce opportunities for threat actors to exploit those connections. What is the Cyberattack Series? In our Cyberattack Series, customers discover how DART investigates unique and notable attacks. For each cyberattack story, we share: How the cyberattack happened. How the compromise was discovered. Microsoft’s investigation and eviction of the threat actor. Strategies to avoid similar cyberattacks. DART is made up of highly skilled investigators, researchers, engineers, and analysts who specialize in handling global security incidents. We’re here for customers with dedicated experts to work with you before, during, and after a cybersecurity incident. Read the latest cyberattack report Learn more To learn more about DART capabilities, please visit our website, or contact your Microsoft account manager or Premier Support contact. To learn more about the cybersecurity incidents described above, including more insights and information on how to protect your own organization, download the full report. To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity. Microsoft Defender Experts Cybersecurity Incident Response See Microsoft Defender Experts Cybersecurity Incident Response posts Related posts September 17 4 min read From guidance to action: Security fundamentals that materiall
Indicators of Compromise
- malware — Atera
- malware — Chisel