Hackers Turn One Compromised Account Into Access to Azure DevOps and Kubernetes
Microsoft attributes to Storm-3068 an intrusion that hijacked one account via password reset, then abused Azure DevOps pipelines to steal Kubernetes credentials.
Microsoft DART attributed an intrusion to Storm-3068, which took over an account through a self-service password reset and registered its own authentication methods for persistence. Using legitimate admin tools and automated scripts, the actor enumerated Azure DevOps projects, repositories, pipelines, and deployment environments, then created a pipeline authorized for over 50 resources to harvest Kubernetes credentials at scale. Seven stolen cluster configuration files were added to a repository; pipeline scripts were also altered to install the Atera remote management agent and the Chisel tunneling utility, exposing the Kubernetes API server via a reverse tunnel. Microsoft recommends phishing-resistant MFA, password-reset monitoring, branch protection, and least-privilege pipeline permissions.