Microsoft attributed a cloud and DevOps intrusion to Storm-3068, which abused a self-service password-reset workflow to take over a user identity and register attacker-controlled authentication methods. Using the account’s legitimate privileges rather than malware or a software exploit, the actor enumerated Azure DevOps projects, repositories, pipelines, deployment environments, and connected cloud resources.
Storm-3068 created and altered Azure DevOps pipelines to deploy a Kubernetes agent and collect cluster kubeconfig files and credentials. One malicious pipeline could access more than 50 resources and services, and investigators found seven stolen Kubernetes configuration files committed to a repository. The actor also modified pipeline scripts to install Atera and Chisel for alternate remote access and reverse tunneling. Microsoft recommends phishing-resistant MFA, limiting self-service password-reset access for privileged accounts, enforcing pipeline approvals and branch protections, constraining pipeline permissions, and applying least privilege across identity, DevOps, and cloud environments.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft DART used identity, Azure DevOps, Git-history, and cloud-infrastructure telemetry to reconstruct the intrusion and worked with the affected organization on containment and remediation. DART also collaborated with Microsoft Threat Intelligence on broader threat context.
Storm-3068 altered pipeline scripts to install the Atera remote-management agent and download Chisel. The actor used Chisel to establish a reverse tunnel to an external IP address, potentially enabling Kubernetes-cluster interaction and exposing the Kubernetes API server.
The actor added seven stolen kubeconfig files to an Azure DevOps repository. The files contained connection details and authentication information for targeted Kubernetes clusters.
Storm-3068 created a pipeline that deployed a kube agent and executed jobs to collect kubeconfig files at scale. The compromised account could deploy a pipeline authorized to access more than 50 resources and authenticated services.
Using the compromised identity's legitimate permissions, the actor enumerated Azure DevOps projects, repositories, pipelines, deployment environments, and connected cloud resources using administrative tools and scripts.
Storm-3068 abused a self-service password-reset process to take over a user account, then registered attacker-controlled authentication methods for persistent access. The intrusion did not rely on malware or a software exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.