{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/storm-3068/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-3068"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Azure DevOps","Kubernetes","Atera"],"_cs_severities":["high"],"_cs_tags":["cloud-security","devops","identity","persistence"],"_cs_type":"threat","_cs_vendors":["Microsoft","Atera"],"content_html":"\u003cp\u003eMicrosoft DART investigators documented Storm-3068 activity where a single compromised identity served as the initial access vector into a target's Azure DevOps and production environments. The actor utilized a self-service password reset process to hijack the account, subsequently registering their own MFA methods to maintain persistence. Once inside, the actor leveraged administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, and pipeline definitions. By identifying trusted deployment paths, Storm-3068 modified CI/CD pipelines to execute malicious code, including the deployment of Atera remote management agents and the Chisel tunneling utility. The objective was to harvest Kubernetes kubeconfig files and establish a reverse tunnel to external infrastructure, providing the actor with broad, persistent access to the organization's cloud environment. This incident demonstrates the risk associated with tightly integrated identity and development pipelines.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained by the actor through a self-service password reset process, hijacking a legitimate user account.\u003c/li\u003e\n\u003cli\u003ePersistence is established by the actor registering their own MFA/authentication methods for the compromised account.\u003c/li\u003e\n\u003cli\u003eThe actor uses the compromised account to enumerate Azure DevOps repositories, deployment environments, and pipeline configurations.\u003c/li\u003e\n\u003cli\u003eMalicious scripts are injected into legitimate CI/CD pipelines, leveraging the identity's permissions to interact with connected cloud services.\u003c/li\u003e\n\u003cli\u003eThe compromised pipeline is used to deploy a kube agent and execute commands to harvest kubeconfig files and cluster authentication details.\u003c/li\u003e\n\u003cli\u003eThe pipeline script is further modified to download and execute the Atera remote management agent for persistent remote access.\u003c/li\u003e\n\u003cli\u003eThe Chisel utility is executed via pipeline scripts to establish a reverse tunnel to an actor-controlled IP, exposing the Kubernetes API server.\u003c/li\u003e\n\u003cli\u003eStolen kubeconfig files are exfiltrated and uploaded to a repository to facilitate subsequent direct access to targeted Kubernetes clusters.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe breach resulted in unauthorized access to over 50 cloud resources, including sensitive Kubernetes clusters. By moving from a single user identity to full pipeline and cloud infrastructure control, the actor gained the capability to manage production environments, potentially exposing or altering data and infrastructure configuration at scale.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize hardening identity and DevOps workflows by auditing access and pipeline configurations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement phishing-resistant MFA for all privileged and standard accounts to prevent identity hijacking via reset processes.\u003c/li\u003e\n\u003cli\u003eEnforce strict branch protection and code review requirements to prevent unauthorized modifications to pipeline definition files.\u003c/li\u003e\n\u003cli\u003eApply principle of least privilege to pipeline service connections to ensure they only possess permissions necessary for their specific deployment task.\u003c/li\u003e\n\u003cli\u003eEstablish monitoring for anomalous activity within Azure DevOps audit logs, specifically focusing on pipeline modifications and unusual user additions to administrative roles.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T19:16:53Z","date_published":"2026-09-29T19:16:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-storm-3068-devops/","summary":"Storm-3068 exploited a compromised identity via self-service password reset to manipulate CI/CD pipelines, harvest Kubernetes credentials, and deploy remote management tools for persistent cloud access.","title":"Storm-3068 Exploitation of Azure DevOps for Cloud Infrastructure Access","url":"https://feed.craftedsignal.io/briefs/2026-09-storm-3068-devops/"}],"language":"en","title":"CraftedSignal Threat Feed - Storm-3068","version":"https://jsonfeed.org/version/1.1"}