Skip to content
Threat Feed
high threat

Storm-3068 Exploitation of Azure DevOps for Cloud Infrastructure Access

Storm-3068 exploited a compromised identity via self-service password reset to manipulate CI/CD pipelines, harvest Kubernetes credentials, and deploy remote management tools for persistent cloud access.

Microsoft DART investigators documented Storm-3068 activity where a single compromised identity served as the initial access vector into a target's Azure DevOps and production environments. The actor utilized a self-service password reset process to hijack the account, subsequently registering their own MFA methods to maintain persistence. Once inside, the actor leveraged administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, and pipeline definitions. By identifying trusted deployment paths, Storm-3068 modified CI/CD pipelines to execute malicious code, including the deployment of Atera remote management agents and the Chisel tunneling utility. The objective was to harvest Kubernetes kubeconfig files and establish a reverse tunnel to external infrastructure, providing the actor with broad, persistent access to the organization's cloud environment. This incident demonstrates the risk associated with tightly integrated identity and development pipelines.

Attack Chain

  1. Initial access is gained by the actor through a self-service password reset process, hijacking a legitimate user account.
  2. Persistence is established by the actor registering their own MFA/authentication methods for the compromised account.
  3. The actor uses the compromised account to enumerate Azure DevOps repositories, deployment environments, and pipeline configurations.
  4. Malicious scripts are injected into legitimate CI/CD pipelines, leveraging the identity's permissions to interact with connected cloud services.
  5. The compromised pipeline is used to deploy a kube agent and execute commands to harvest kubeconfig files and cluster authentication details.
  6. The pipeline script is further modified to download and execute the Atera remote management agent for persistent remote access.
  7. The Chisel utility is executed via pipeline scripts to establish a reverse tunnel to an actor-controlled IP, exposing the Kubernetes API server.
  8. Stolen kubeconfig files are exfiltrated and uploaded to a repository to facilitate subsequent direct access to targeted Kubernetes clusters.

Impact

The breach resulted in unauthorized access to over 50 cloud resources, including sensitive Kubernetes clusters. By moving from a single user identity to full pipeline and cloud infrastructure control, the actor gained the capability to manage production environments, potentially exposing or altering data and infrastructure configuration at scale.

Recommendation

Prioritize hardening identity and DevOps workflows by auditing access and pipeline configurations.

  • Implement phishing-resistant MFA for all privileged and standard accounts to prevent identity hijacking via reset processes.
  • Enforce strict branch protection and code review requirements to prevent unauthorized modifications to pipeline definition files.
  • Apply principle of least privilege to pipeline service connections to ensure they only possess permissions necessary for their specific deployment task.
  • Establish monitoring for anomalous activity within Azure DevOps audit logs, specifically focusing on pipeline modifications and unusual user additions to administrative roles.

Immediate actions

Review and restrict access to self-service password reset portals for high-privilege accounts

Identity Team 24h

Audit CI/CD pipeline definitions for unauthorized modifications or embedded remote management scripts

DevSecOps 48h

Threat Hunt

Search Azure DevOps audit logs for unauthorized pipeline modifications or creation of new service connections

T1059 high high confidence hunt now

Data: Azure DevOps audit logs

Mitigations

Enable phishing-resistant MFA for all users interacting with CI/CD and cloud management consoles

immediate Identity Team

Account hijacking and MFA registration