<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Storm-3068 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/storm-3068/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 19:16:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/storm-3068/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Storm-3068 Exploitation of Azure DevOps for Cloud Infrastructure Access</title><link>https://feed.craftedsignal.io/briefs/2026-09-storm-3068-devops/</link><pubDate>Tue, 29 Sep 2026 19:16:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-storm-3068-devops/</guid><description>Storm-3068 exploited a compromised identity via self-service password reset to manipulate CI/CD pipelines, harvest Kubernetes credentials, and deploy remote management tools for persistent cloud access.</description><content:encoded><![CDATA[<p>Microsoft DART investigators documented Storm-3068 activity where a single compromised identity served as the initial access vector into a target's Azure DevOps and production environments. The actor utilized a self-service password reset process to hijack the account, subsequently registering their own MFA methods to maintain persistence. Once inside, the actor leveraged administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, and pipeline definitions. By identifying trusted deployment paths, Storm-3068 modified CI/CD pipelines to execute malicious code, including the deployment of Atera remote management agents and the Chisel tunneling utility. The objective was to harvest Kubernetes kubeconfig files and establish a reverse tunnel to external infrastructure, providing the actor with broad, persistent access to the organization's cloud environment. This incident demonstrates the risk associated with tightly integrated identity and development pipelines.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is gained by the actor through a self-service password reset process, hijacking a legitimate user account.</li>
<li>Persistence is established by the actor registering their own MFA/authentication methods for the compromised account.</li>
<li>The actor uses the compromised account to enumerate Azure DevOps repositories, deployment environments, and pipeline configurations.</li>
<li>Malicious scripts are injected into legitimate CI/CD pipelines, leveraging the identity's permissions to interact with connected cloud services.</li>
<li>The compromised pipeline is used to deploy a kube agent and execute commands to harvest kubeconfig files and cluster authentication details.</li>
<li>The pipeline script is further modified to download and execute the Atera remote management agent for persistent remote access.</li>
<li>The Chisel utility is executed via pipeline scripts to establish a reverse tunnel to an actor-controlled IP, exposing the Kubernetes API server.</li>
<li>Stolen kubeconfig files are exfiltrated and uploaded to a repository to facilitate subsequent direct access to targeted Kubernetes clusters.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The breach resulted in unauthorized access to over 50 cloud resources, including sensitive Kubernetes clusters. By moving from a single user identity to full pipeline and cloud infrastructure control, the actor gained the capability to manage production environments, potentially exposing or altering data and infrastructure configuration at scale.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize hardening identity and DevOps workflows by auditing access and pipeline configurations.</p>
<ul>
<li>Implement phishing-resistant MFA for all privileged and standard accounts to prevent identity hijacking via reset processes.</li>
<li>Enforce strict branch protection and code review requirements to prevent unauthorized modifications to pipeline definition files.</li>
<li>Apply principle of least privilege to pipeline service connections to ensure they only possess permissions necessary for their specific deployment task.</li>
<li>Establish monitoring for anomalous activity within Azure DevOps audit logs, specifically focusing on pipeline modifications and unusual user additions to administrative roles.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>cloud-security</category><category>devops</category><category>identity</category><category>persistence</category></item></channel></rss>