Full Report
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.
Analysis Summary
# Incident Report: Storm-3068 DevOps & Cloud Infrastructure Compromise
## Executive Summary
The threat actor Storm-3068 successfully compromised a single user identity via a self-service password reset, subsequently gaining access to the organization's Azure DevOps environment. By exploiting trusted CI/CD pipelines, the actor harvested Kubernetes credentials and deployed remote management tools, effectively moving from a compromised identity to broad cloud infrastructure access. The incident was mitigated by Microsoft DART, highlighting the risks of interconnected development and production environments.
## Incident Details
- **Discovery Date:** Q3 2026 (Reported)
- **Incident Date:** Not explicitly disclosed (Q3 2026 reporting cycle)
- **Affected Organization:** Not disclosed
- **Sector:** Not disclosed
- **Geography:** Global/Cloud-based
## Timeline of Events
### Initial Access
- **Date/Time:** T0
- **Vector:** Self-Service Password Reset (SSPR) exploitation.
- **Details:** Storm-3068 gained access to a user account by completing a password reset and registering their own secondary authentication methods to establish full control.
### Lateral Movement
- **Azure DevOps Enumeration:** The actor used legitimate administrative tools and automated scripts to map repositories, projects, and deployment pipelines.
- **Pipeline Exploitation:** Created malicious pipelines and modified existing ones to bridge the gap between the development environment and cloud infrastructure.
### Data Exfiltration/Impact
- **Credential Harvesting:** Executed jobs to collect `kubeconfig` files, providing authentication information for Kubernetes clusters.
- **Resource Access:** The compromised account and pipelines granted access to over 50 cloud resources.
### Detection & Response
- **Detection:** Identified through Azure DevOps audit logs and Git version history monitoring.
- **Response:** Microsoft DART investigated the activity, evicted the threat actor, and performed a forensic review of the CI/CD environment.
## Attack Methodology
- **Initial Access:** Exploitation of Self-Service Password Reset (SSPR).
- **Persistence:** Registration of attacker-controlled MFA/Authentication methods.
- **Privilege Escalation:** Leveraging compromised identity permissions to create/modify DevOps pipelines.
- **Defense Evasion:** Use of legitimate administrative tools (Living-off-the-Land) and automated scripts; modifying Git history.
- **Credential Access:** Harvesting `kubeconfig` files and service connection credentials.
- **Discovery:** Enumeration of Azure DevOps repositories, projects, and connected cloud resources.
- **Lateral Movement:** Using DevOps pipelines to deploy agents into production cloud environments.
- **Collection:** Gathering cluster connection details and authentication tokens.
- **Exfiltration:** Establishing a reverse tunnel to an external IP via Chisel.
- **Impact:** Potential for full control over Kubernetes clusters and cloud-hosted applications.
## Impact Assessment
- **Financial:** Not disclosed (potentially high due to incident response costs).
- **Data Breach:** Compromise of internal source code and cloud credentials.
- **Operational:** Disruption of CI/CD workflows; potential unauthorized access to production Kubernetes environments.
- **Reputational:** High risk due to the compromise of "keys to the kingdom" (infrastructure access).
## Indicators of Compromise
- **Network:** Reverse tunnel connections to external IP addresses via Chisel.
- **File:** Deployment of `Atera` remote management agent; `Chisel` tunneling utility binaries.
- **Behavioral:** Unexpected SSPR activity; creation of new DevOps pipelines authorized for numerous resources; unauthorized modifications to pipeline scripts.
## Response Actions
- **Containment:** Disabling the compromised identity and terminating active sessions.
- **Eradication:** Removal of malicious pipelines, deletion of unauthorized authentication methods, and removal of Atera/Chisel tools.
- **Recovery:** Rotating all potentially compromised Kubernetes credentials and service principal keys.
## Lessons Learned
- **Identity is the Perimeter:** A single account without sufficient SSPR protections can lead to total infrastructure compromise.
- **Pipeline Trust:** Trusted CI/CD pipelines can be weaponized to bypass traditional network security controls between Dev and Prod.
- **Visibility:** Comprehensive logging (Audit logs, Git history) is essential for detecting "living-off-the-land" techniques in the cloud.
## Recommendations
- **Strengthen SSPR:** Implement stricter verification for self-service password resets and monitor for new MFA registrations.
- **Pipeline Security:** Implement "least privilege" for CI/CD service connections and require manual approvals for pipeline changes affecting production.
- **Continuous Monitoring:** Audit Azure DevOps activity for unusual enumeration patterns or the introduction of unauthorized binaries like Chisel.
- **Secret Management:** Use short-lived credentials and managed identities instead of long-lived `kubeconfig` files where possible.