Executive Summary
Storm-3068 threat actors compromised a user account through a self-service password reset process and established persistent access by registering their own authentication methods. The attackers then exploited Azure DevOps repositories and pipelines to harvest Kubernetes credentials at scale, creating malicious deployment pipelines that collected kubeconfig files from over 50 resources. By leveraging legitimate identity and cloud services rather than traditional malware, the threat actor demonstrated how a single compromised identity can provide pathways to development platforms, cloud resources, and production environments when these systems are tightly integrated.
This incident exemplifies the growing trend of identity-driven attacks targeting cloud-native development environments, highlighting critical security gaps in DevOps workflows and the need for enhanced protection of interconnected cloud infrastructure components.
Why This Matters Now
Identity-driven attacks are rapidly increasing as organizations adopt cloud-native development practices, making the intersection of identity, DevOps, and cloud infrastructure a prime target for sophisticated threat actors seeking persistent access to critical business systems.
Attack Path Analysis
Storm-3068 initiated the attack by compromising a user account through self-service password reset and registering persistent authentication methods. The threat actor escalated privileges by leveraging the compromised account's Azure DevOps access and administrative permissions. They moved laterally through Azure DevOps environments, enumerating repositories, pipelines, and deployment configurations to map the development infrastructure. Command and control was established through modified development pipelines that deployed Atera remote management agents and Chisel tunneling utilities. Exfiltration occurred via malicious pipeline jobs that harvested Kubernetes credentials at scale, collecting over 50 kubeconfig files containing cluster authentication details. The impact included unauthorized access to production Kubernetes environments and potential exposure of sensitive cluster resources.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Storm-3068 gained access to a user account through self-service password reset process and registered their own authentication methods for persistent access
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Brute Force: Password Guessing
Modify Authentication Process: Conditional Access Policies
Account Discovery: Cloud Account
Data from Information Repositories: Code Repositories
Account Manipulation: Additional Cloud Credentials
Process Injection: Dynamic-link Library Injection
Remote Services: Cloud Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: IA-2
DORA – ICT Third-Party Risk Management
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Removal of Access Rights
Control ID: A.9.2.6
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Identity-driven attacks targeting Azure DevOps pipelines expose source code, Kubernetes credentials, and development infrastructure through compromised developer accounts and CI/CD systems.
Information Technology/IT
Storm-3068's exploitation of self-service password resets and cloud infrastructure demonstrates critical vulnerabilities in identity management and zero trust segmentation controls.
Financial Services
HIPAA and PCI compliance violations through lateral movement and data exfiltration threaten regulated financial institutions using cloud-native development and deployment pipelines.
Health Care / Life Sciences
Healthcare organizations face severe HIPAA compliance risks from identity compromises enabling unauthorized access to patient data through cloud infrastructure and development environments.
Sources
- Beyond source code: A path to the keys to the kingdomhttps://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/Verified
- Microsoft Defender Experts Cybersecurity Incident Responsehttps://www.microsoft.com/en-us/security/business/microsoft-defender-expertsVerified
- CISA Cloud Security Technical Reference Architecturehttps://www.cisa.gov/resources-tools/resources/cloud-security-technical-reference-architectureVerified
- NIST Cybersecurity Framework - Identity Managementhttps://www.nist.gov/cyberframeworkVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack's blast radius by constraining lateral movement between Azure DevOps and Kubernetes environments. The segmented architecture could limit credential harvesting scope and restrict unauthorized access to production cluster resources.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial account compromise would likely still occur, but subsequent access to cloud resources could be constrained through identity-aware routing and workload isolation policies that limit the compromised account's reachability across environments.
Control: Zero Trust Segmentation
Mitigation: Administrative access to Azure DevOps may remain possible, but zero trust segmentation could likely constrain the scope of enumerable resources and limit visibility into sensitive development infrastructure through workload isolation boundaries.
Control: East-West Traffic Security
Mitigation: Enumeration activities would likely be constrained as east-west traffic controls could limit communication paths between Azure DevOps components and connected Kubernetes environments, reducing the attacker's ability to map the full development infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Pipeline modifications may still occur, but multicloud visibility controls would likely detect and constrain the establishment of unauthorized tunneling connections, limiting the attacker's ability to maintain persistent command channels through monitored traffic flows.
Control: Egress Security & Policy Enforcement
Mitigation: Credential harvesting activities would likely be constrained through egress controls that limit data movement from Kubernetes environments, reducing the volume of kubeconfig files that could be collected and transferred to external repositories.
While some Kubernetes credentials may remain compromised, the overall impact would likely be reduced through network segmentation that limits cluster reachability and constrains the scope of accessible production resources.
Impact at a Glance
Affected Business Functions
- Software Development Operations
- Cloud Infrastructure Management
- DevOps Pipeline Operations
- Kubernetes Cluster Management
Estimated downtime: 7 days
Estimated loss: $150,000
Source code repositories, Kubernetes configuration files (kubeconfig), service connection credentials, deployment pipeline configurations, and authentication tokens for over 50 cloud resources. The threat actor gained access to sensitive development infrastructure secrets that could enable further lateral movement and persistent access to production environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement from compromised development accounts to production Kubernetes environments
- • Deploy egress security controls with policy enforcement to detect and block unauthorized outbound connections including reverse tunnels and remote access tools like Atera and Chisel
- • Enable multicloud visibility and control systems to monitor Azure DevOps pipeline modifications and detect anomalous automation patterns in development workflows
- • Strengthen east-west traffic security between development and production environments to limit unauthorized service-to-service communications from compromised pipelines
- • Implement threat detection and anomaly response capabilities to baseline normal development activity and alert on credential harvesting behaviors and unauthorized remote access tool deployment



