Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Microsoft attributes an Azure DevOps intrusion to Storm-3068, who abused password resets to hijack accounts and steal Kubernetes kubeconfig files via malicious pipelines.
Microsoft detailed a Storm-3068 intrusion that began with self-service password reset abuse, registration of attacker-controlled authentication methods, and removal of legitimate MFA for persistent access. The actor enumerated Azure DevOps projects and pipelines, then created a malicious pipeline authorized to access more than 50 resources and ran jobs using the DUMPCLUSTERNAME pattern to dump kubeconfig files, committing them to an existing repository. Pipelines were also modified to deploy the Atera remote management agent and the Chisel tunneling utility for persistence and Kubernetes API access. The campaign escalated from identity compromise to supply-chain and production infrastructure risk within hours.
- Intrusion began with self-service password reset abuse and MFA method removal.
- Malicious Azure DevOps pipeline with 50+ resource access dumped kubeconfig files.
- Stolen kubeconfigs committed to an existing repo to blend with DevOps workflows.
- Atera RMM and Chisel deployed for persistence and Kubernetes API tunneling.
- Monitor password-reset anomalies; enforce least-privilege pipeline and service identities.
Full article678 words · extracted from gbhackers.com · click to collapse
Microsoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments.
The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have broad permissions.
The intrusion began with the successful abuse of a self-service password reset process.
After gaining control of the targeted account, Storm-3068 registered attacker-controlled authentication methods and removed legitimate multifactor authentication methods, creating persistent access.
The actor then used valid credentials and legitimate cloud administration capabilities rather than relying on malware exploits or a conventional endpoint-based attack chain.
Azure DevOps became the key pivot point. The compromised account enabled the threat actor to enumerate repositories, projects, deployment environments, pipelines, and service relationships.
This intelligence gave the attackers a map of the organization’s development and cloud operations, including trusted deployment paths and connected infrastructure.
In modern DevOps environments, repositories and pipeline configurations can expose far more than source code: they may reveal service connections, secrets-management workflows, cloud resources, and deployment identities.
One malicious pipeline was authorized to access more than 50 resources.
Its central objective was to retrieve Kubernetes kubeconfig files, which can include Kubernetes API server endpoints, cluster identifiers, certificate authority data, namespaces, user context, and authentication material for service accounts.
The attackers deployed a kubeagent by downloading and executing a third-party script through the pipeline.
They then created multiple jobs using the DUMPCLUSTERNAME pattern to extract kubeconfig contents and store the files locally.
Storm-3068 Hijacks Azure
Microsoft’s incident-response investigation found that, Storm-3068 created and deleted Azure DevOps pipelines using administrative permissions associated with the hijacked account.

The stolen files were subsequently committed to a targeted repository inside an existing kubeconfigs directory, blending attacker activity with normal DevOps workflows.
This step represented a critical privilege escalation because the kubeconfig files could provide direct interaction with Kubernetes clusters independently of Azure DevOps.
Storm-3068 also modified pipelines to deploy the Atera remote management agent and the Chisel tunneling utility. Atera can provide remote-administration functionality, while Chisel can proxy Kubernetes API traffic and establish reverse tunnels to attacker-controlled infrastructure.
Together, these tools could allow the threat actor to retain access, communicate with compromised environments, and reach Kubernetes control-plane services through trusted pipeline execution paths.
The campaign highlights a broader security issue facing cloud-native organizations: CI/CD systems increasingly bridge identity providers, source repositories, secrets, cloud subscriptions, Kubernetes clusters, and production workloads.
A developer or administrator account with excessive permissions can therefore become a high-value target.
In this case, a single identity compromise allowed the actor to move from password-reset abuse to persistent identity control, Azure DevOps reconnaissance, pipeline manipulation, Kubernetes credential collection, and cloud-environment discovery within hours.
Defenders should monitor anomalous self-service password reset activity, especially repeated reset attempts from a single IP address or attempts against several users in a short period.
Privileged accounts should be protected with phishing-resistant MFA and reviewed to determine whether self-service password reset is appropriate.
Organizations should also enforce branch protections, require pull-request approvals, restrict direct commits to critical branches, and limit who can create, alter, or execute build and deployment pipelines.
Most importantly, pipeline identities and service connections should follow least-privilege principles.
Kubernetes credentials should not be broadly retrievable by pipelines, should be short-lived where possible, and should be rotated immediately following suspected pipeline compromise.
Azure DevOps audit logs, Git history, pipeline execution records, MFA registration events, Intune device-enrollment telemetry, and Kubernetes API audit logs should be correlated during investigation.
Storm-3068’s operation reinforces that trusted DevOps automation can become an attacker’s most effective access mechanism.
Securing CI/CD pipelines now requires the same rigor traditionally applied to privileged identity management and production infrastructure.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.