Microsoft: Storm-3068 turned one password-reset account takeover into Kubernetes access via Azure DevOps pipelines
Microsoft DART attributes to Storm-3068 an intrusion that began with a self-service password reset account takeover, then used a malicious Azure DevOps pipeline authorized against 50+ resources to steal seven kubeconfig files and expose the Kubernetes API…
Microsoft's Detection and Response Team (DART) attributed to Storm-3068 an intrusion that began with a compromised user account obtained through a self-service password reset, after which the actor registered its own authentication methods to take full control of the identity; GBHackers additionally reports the actor removed the victim's legitimate MFA methods to maintain persistence. Using legitimate administrative tools and automated scripts, the actor enumerated Azure DevOps projects, repositories, pipelines, and deployment environments, then created a malicious pipeline authorized against more than 50 resources. Per GBHackers, the pipeline ran jobs using a 'DUMPCLUSTERNAME' naming pattern to dump kubeconfig files, and the seven stolen kubeconfig files were committed to an existing repository to blend with legitimate DevOps workflows. Pipeline scripts were also modified to install the Atera remote management (RMM) agent and the Chisel tunneling utility, establishing a reverse tunnel to an external IP that exposed the Kubernetes API server. Microsoft notes that no malware or software exploits were used — the intrusion relied entirely on legitimate identity and cloud services — and GBHackers reports the campaign escalated from identity compromise to supply-chain and production-infrastructure risk within hours. Microsoft recommends phishing-resistant MFA, monitoring of password-reset anomalies, pipeline approvals, branch protection, and least-privilege identity and pipeline permissions. All three reports (Microsoft Security Blog, 2026-09-29; GBHackers, 2026-09-30; Cyber Security News, 2026-09-30) are consistent; no source disagreements were found.
- Attribution: Microsoft DART attributes the intrusion to Storm-3068 (Microsoft Security Blog, 2026-09-29).
- Initial access: account takeover via self-service password reset; the actor registered its own authentication methods to take full control of the identity, and per GBHackers also removed the victim's legitimate MFA methods for persistence.
- Reconnaissance: the actor used legitimate administrative tools and automated scripts to enumerate Azure DevOps projects, repositories, pipelines, and deployment environments.
- Credential theft: a malicious pipeline authorized against more than 50 resources harvested seven kubeconfig files; GBHackers reports the jobs used a 'DUMPCLUSTERNAME' naming pattern and that the stolen files were committed to an existing…
- Persistence and access: modified pipeline scripts installed the Atera RMM agent and the Chisel tunneling utility, establishing a reverse tunnel to an external IP that exposed the Kubernetes API server.
- Technique: no malware or software exploits were used; the intrusion relied entirely on legitimate identity and cloud services (Microsoft).
- Impact: GBHackers reports the campaign escalated from identity compromise to supply-chain and production-infrastructure risk within hours.
- Defenses recommended: phishing-resistant MFA, monitoring of password-reset anomalies, pipeline approvals, branch protection, and least-privilege identity and pipeline permissions.
Coverage timelineoldest first · each row is one article
- · 1d agoBeyond source code: A path to the keys to the kingdom
Microsoft Security Blog· 62
Microsoft DART details how Storm-3068 hijacked an account via self-service password reset, then used Azure DevOps pipelines to harvest Kubernetes credentials across 50+ resources.
- · 18h agoStorm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
GBHackers· 68
Microsoft attributes an Azure DevOps intrusion to Storm-3068, who abused password resets to hijack accounts and steal Kubernetes kubeconfig files via malicious pipelines.
- · 14h agoHackers Turn One Compromised Account Into Access to Azure DevOps and Kubernetes
Cyber Security News· 58