Beyond source code: A path to the keys to the kingdom
Microsoft DART details how Storm-3068 hijacked an account via self-service password reset, then used Azure DevOps pipelines to harvest Kubernetes credentials across 50+ resources.
Microsoft's Detection and Response Team investigated Storm-3068 activity that began with a compromised user account obtained through a self-service password reset, with the actor registering its own authentication methods to take full control of the identity. Using legitimate administrative tools, the actor enumerated Azure DevOps repositories, projects, pipelines, and deployment environments, then created a malicious pipeline authorized against more than 50 resources to deploy a kube agent and collect kubeconfig files. Seven stolen kubeconfig files were added to a repository, and the Atera RMM agent plus the Chisel tunneling utility were installed to establish a reverse tunnel exposing the Kubernetes API server. No malware or software exploits were used; the intrusion relied entirely on legitimate identity and cloud services.
- Initial access via self-service password reset; actor registered own authentication methods.
- Malicious Azure DevOps pipeline harvested seven kubeconfig files across 50+ authorized resources.
- Atera RMM and Chisel reverse tunnel deployed for persistence and Kubernetes API exposure.
- Microsoft urges phishing-resistant MFA, pipeline approvals, and least-privilege identity controls.
Full article1,033 words · extracted from microsoft.com · click to collapse
What began as a single compromised identity quickly expanded into an organization’s development and cloud environments. In our latest Cyberattack Series report, we examine how the Microsoft Detection and Response Team (DART)—the team that delivers Microsoft Defender Experts Cybersecurity Incident Response—investigated activity by Storm-3068, a threat actor that turned a successful self-service password reset into access to Azure DevOps, development pipelines, and Kubernetes resources. By leveraging legitimate identity and cloud services rather than malware or software exploits, the threat actor established persistent access, enumerated repositories, and obtained credentials that opened a path into connected cloud infrastructure. This case highlights a growing challenge for defenders: when identities, source code, pipelines, and production environments are tightly linked, a single account compromise can provide a pathway to much broader access across the organization. Read on to learn more or access the full report.
What happened?
The intrusion began with Storm-3068 gaining access to a user account through a self-service password reset process and then taking full control of the identity by registering its own authentication methods. With persistent access established, the threat actor shifted its focus to Azure DevOps using legitimate administrative tools and automated scripts to enumerate repositories, projects, pipelines, and deployment environments.
TACTIC: Trusted pipelines were exploited
Rather than deploying malware, the threat actor modified development pipelines to collect Kubernetes credentials and expand access into cloud infrastructure.
Azure DevOps proved to be a high-value target because it sat at the intersection of identity, software development, and cloud operations. By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.
The investigation revealed that Storm-3068 created a malicious pipeline designed to harvest Kubernetes credentials at scale. The pipeline deployed a kube agent and executed multiple jobs intended to collect kubeconfig files containing cluster connection details and authentication information. Leveraging the permissions of the compromised account, the threat actor deployed the pipeline that was authorized to access more than 50 resources and authenticated to services. In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. These tools were deployed in an attempt to provide the threat actor with alternative mechanisms for remote access and to expose the Kubernetes API server. Chisel commands were executed to establish a reverse tunnel to an external IP address to enable potential remote interaction with the Kubernetes clusters.
Using Azure DevOps audit logs and Git version history, investigators reconstructed the next stage of the intrusion. The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.
INSIGHT: Azure DevOps can reveal much more than source code
Repositories, pipelines, service connections, and deployment settings can provide threat actors with a roadmap to an organization’s broader environment.
How did Microsoft respond?
Once engaged, DART moved quickly to investigate the intrusion and disrupt the threat actor’s access. By analyzing telemetry across identity systems, development platforms, and cloud infrastructure, the team pieced together how the cyberattack unfolded and identified where the threat actor had expanded beyond the initial compromise.
Throughout the engagement, DART worked side by side with the customer, sharing findings through daily briefings and providing prioritized guidance to support containment and remediation efforts. As new details emerged, this close coordination helped the customer make informed decisions and respond quickly. DART also collaborated with Microsoft Threat Intelligence to place the activity in a broader threat context, helping refine the investigation and focus response efforts across affected environments.
Beyond containing the intrusion, DART provided recommendations to help improve resilience and reduce opportunities for future compromise. Read the full report to learn how the investigation uncovered the extent of the threat actor’s access and the key lessons organizations can apply to defend against similar identity-driven attacks.
What can customers do to strengthen their defenses?
While the attack began with a compromised identity, its impact grew as the threat actor moved through development and cloud environments. Organizations can reduce similar risks by focusing on:
- Monitoring password reset activity for unusual patterns, including repeated reset attempts or activity targeting multiple users.
- Strengthening protection for privileged accounts by limiting exposure to self-service password reset workflows and requiring phishing-resistant multifactor authentication.
- Requiring approvals for code changes and enforcing branch protection policies to prevent unauthorized modifications.
- Restricting direct commits to critical branches so changes follow established review and approval processes.
- Controlling pipeline permissions and limiting who can create, modify, or execute build and deployment pipelines.
- Applying least-privilege access principles across identities, development platforms, and cloud resources to minimize the impact of a compromised account.
INSIGHT: Identities are the new attack path
This incident demonstrates how a single compromised identity can provide access to development platforms, cloud resources, and production environments when those systems are tightly connected.
As this case demonstrates, a single compromised identity can become a pathway to much broader access when development platforms, deployment pipelines, and cloud infrastructure are tightly connected. Regular reviews of identity, DevOps, and cloud security controls can help reduce opportunities for threat actors to exploit those connections.
What is the Cyberattack Series?
In our Cyberattack Series, customers discover how DART investigates unique and notable attacks. For each cyberattack story, we share:
- How the cyberattack happened.
- How the compromise was discovered.
- Microsoft’s investigation and eviction of the threat actor.
- Strategies to avoid similar cyberattacks.
DART is made up of highly skilled investigators, researchers, engineers, and analysts who specialize in handling global security incidents. We’re here for customers with dedicated experts to work with you before, during, and after a cybersecurity incident.
Learn more
To learn more about DART capabilities, please visit our website, or contact your Microsoft account manager or Premier Support contact. To learn more about the cybersecurity incidents described above, including more insights and information on how to protect your own organization, download the full report.
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.