Storm-3068 Exploits Azure DevOps in Cloud-Focused Intrusion
Microsoft has uncovered a sophisticated cloud-based attack attributed to the threat actor Storm-3068, which leveraged a compromised user account to abuse Azure DevOps, steal Kubernetes credentials, and gain potential access to connected cloud environments. The campaign underscores how identity compromise can rapidly escalate into a software supply-chain and production-infrastructure breach when development platforms hold excessive permissions.
The intrusion began with the abuse of a self-service password reset process, allowing Storm-3068 to take control of a targeted account. The attackers then registered malicious authentication methods, removed legitimate multi-factor authentication (MFA), and established persistent access all without relying on malware or traditional endpoint exploits.
Using the hijacked account, the threat actor enumerated Azure DevOps repositories, projects, pipelines, and service connections, mapping the organization’s development and cloud operations. A key focus was Kubernetes kubeconfig files, which contain sensitive data such as API server endpoints, cluster identifiers, and authentication material. Storm-3068 deployed a malicious pipeline to extract these files, storing them in a repository under the guise of normal DevOps activity.
The attackers further modified pipelines to deploy Atera (a remote management tool) and Chisel (a tunneling utility), enabling persistent access and communication with compromised environments. These tools allowed the threat actor to proxy Kubernetes API traffic and establish reverse tunnels to attacker-controlled infrastructure.
The incident highlights a critical security challenge: CI/CD systems often bridge identity providers, source repositories, secrets, and cloud resources, making them high-value targets. In this case, a single identity compromise led to password-reset abuse, persistent access, pipeline manipulation, and Kubernetes credential theft within hours.
Microsoft’s investigation revealed that privileged accounts with broad permissions remain prime targets. The attack also demonstrated how trusted DevOps automation can be weaponized, emphasizing the need for least-privilege access, branch protections, and pipeline security controls. Organizations are advised to monitor anomalous password reset activity, enforce phishing-resistant MFA, and correlate Azure DevOps, Git, and Kubernetes audit logs for detection.
Storm-3068’s operation serves as a reminder that securing CI/CD pipelines requires the same rigor as privileged identity and production infrastructure management.
Source: https://gbhackers.com/storm-3068-hijacks-azure/
Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-threat-intelligence
"id": "mic1790757162",
"linkid": "microsoft-threat-intelligence",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization'}],
'attack_vector': 'Compromised user account, Abuse of self-service password '
'reset process, Malicious pipeline deployment',
'data_breach': {'file_types_exposed': 'kubeconfig files',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Kubernetes credentials, '
'Authentication material'},
'description': 'Microsoft has uncovered a sophisticated cloud-based attack '
'attributed to the threat actor Storm-3068, which leveraged a '
'compromised user account to abuse Azure DevOps, steal '
'Kubernetes credentials, and gain potential access to '
'connected cloud environments. The campaign underscores how '
'identity compromise can rapidly escalate into a software '
'supply-chain and production-infrastructure breach when '
'development platforms hold excessive permissions.',
'impact': {'data_compromised': 'Kubernetes kubeconfig files (API server '
'endpoints, cluster identifiers, '
'authentication material)',
'operational_impact': 'Potential access to connected cloud '
'environments, Weaponization of DevOps '
'automation',
'systems_affected': 'Azure DevOps, Kubernetes clusters, CI/CD '
'pipelines'},
'initial_access_broker': {'backdoors_established': 'Malicious authentication '
'methods, Removal of '
'legitimate MFA, '
'Deployment of Atera and '
'Chisel',
'entry_point': 'Compromised user account via '
'self-service password reset abuse',
'high_value_targets': 'Kubernetes credentials, '
'CI/CD pipelines'},
'investigation_status': 'Investigation completed',
'lessons_learned': 'CI/CD systems bridge identity providers, source '
'repositories, secrets, and cloud resources, making them '
'high-value targets. A single identity compromise can lead '
'to rapid escalation. Privileged accounts with broad '
'permissions are prime targets. Trusted DevOps automation '
'can be weaponized.',
'post_incident_analysis': {'corrective_actions': 'Enforce least-privilege '
'access, implement branch '
'protections, secure '
'pipelines, monitor '
'anomalous activity, enforce '
'phishing-resistant MFA, '
'correlate audit logs',
'root_causes': 'Identity compromise, Excessive '
'permissions in Azure DevOps, Lack '
'of phishing-resistant MFA, Weak '
'pipeline security controls'},
'recommendations': 'Enforce least-privilege access, implement branch '
'protections, secure pipelines, monitor anomalous password '
'reset activity, enforce phishing-resistant MFA, correlate '
'Azure DevOps, Git, and Kubernetes audit logs.',
'references': [{'source': 'Microsoft'}],
'response': {'enhanced_monitoring': 'Correlation of Azure DevOps, Git, and '
'Kubernetes audit logs',
'third_party_assistance': 'Microsoft investigation'},
'threat_actor': 'Storm-3068',
'title': 'Storm-3068 Exploits Azure DevOps in Cloud-Focused Intrusion',
'type': 'Cloud-based intrusion, Supply-chain attack, Credential theft',
'vulnerability_exploited': 'Excessive permissions in Azure DevOps, Lack of '
'phishing-resistant MFA, Weak pipeline security '
'controls'}