CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Storm-3068

actor · actor:storm-3068 single-source

Microsoft designator for an actor that turned a successful self-service password reset into Azure DevOps pipeline abuse, Atera and Chisel tooling and stolen Kubernetes credentials; Microsoft gives no attribution, victim or date (Microsoft Defender Experts, 2026-09-29).

Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Microsoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts

Defender insights

What each entry about Storm-3068 tells a defender to do, newest first.

2026-09-30NOTABLEMicrosoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials

Triage

Story timeline

  1. 2026-09-30Storm-3068: a successful self-service password reset became Azure DevOps pipeline abuse and stolen Kubernetes credentials, with no malware or exploit
    active-threatsMicrosoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials

Hunting pivots

Affected products
ATT&CK techniques (8 across 9 tactics)

8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts: Cloud Accounts
  • ExecutionSoftware Deployment Tools
  • PersistenceValid Accounts: Cloud Accounts · Account Manipulation: Device Registration
  • Privilege EscalationValid Accounts: Cloud Accounts · Account Manipulation: Device Registration
  • StealthValid Accounts: Cloud Accounts
  • Credential AccessUnsecured Credentials: Credentials In Files
  • Lateral MovementSoftware Deployment Tools
  • CollectionData from Information Repositories: Code Repositories
  • Command and ControlIngress Tool Transfer · Remote Access Tools · Protocol Tunneling

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Execution TA0002

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Lateral Movement TA0008

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗

Entries about Storm-3068 (1)

2026-09-30 · view entry permalink →

NOTABLENATOB2

Storm-3068: a successful self-service password reset became Azure DevOps pipeline abuse and stolen Kubernetes credentials, with no malware or exploit

Microsoft's Defender Experts incident-response team (DART) describes a malware-free, exploit-free intrusion by the actor it designates Storm-3068 that began when the actor gained access to a user account through a self-service password reset and took full control of the identity by registering its own authentication methods (Microsoft Defender Experts, 2026-09-29). Microsoft does not say how the reset challenge was passed. With that persistent access, the actor used legitimate administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, pipelines and deployment environments, then created a malicious pipeline that deployed a kube agent and ran jobs to collect kubeconfig files; that pipeline inherited the compromised account's permissions and was authorized to access more than 50 resources (Microsoft Defender Experts, 2026-09-29). The actor also modified pipeline scripts to install the Atera remote-management agent and download the Chisel tunneling utility, and ran Chisel to open a reverse tunnel to an external address, which Microsoft describes as an attempt at alternative remote access and at exposing the Kubernetes API server (Microsoft Defender Experts, 2026-09-29). Investigators rebuilt the sequence from Azure DevOps audit logs and Git version history and found seven stolen kubeconfig files committed to a repository (Microsoft Defender Experts, 2026-09-29). The full report adds that the actor registered a new MFA method and deleted the account's legitimate MFA methods, started the kube agent by downloading and running a third-party script with several jobs, saved the kubeconfig files into an existing kubeconfigs folder of the target repository (each holding a cluster API endpoint, certificate-authority data and a service-account token), and expanded access in a matter of hours rather than days (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29).

Where it surfaces: identity-provider audit logs show a completed password reset followed by new authentication-method registrations on the same account (Microsoft Defender Experts, 2026-09-29), and the full report's attack flow adds deletion of the legitimate methods (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29), while Microsoft advises watching for repeated resets or resets against many users; DevOps audit logs show one identity enumerating repositories and pipelines and then creating or modifying pipelines; Git history shows pipeline scripts that install a remote-management agent or download a tunneling tool, and kubeconfig files committed to a repository; build-agent egress shows a reverse tunnel to an external address (Microsoft Defender Experts, 2026-09-29). Microsoft's recommended controls are to keep privileged accounts out of self-service password reset or protect them with phishing-resistant multifactor authentication, enforce branch protection and approvals for code changes, restrict direct commits to critical branches, limit who can create, modify or run pipelines, and apply least privilege across identity, DevOps and cloud (Microsoft Defender Experts, 2026-09-29).

Triage: a user completing a password reset and then registering authentication methods is routine. The sequence that separates this activity is the same identity, right after the reset, enumerating Azure DevOps repositories and pipelines in bulk and then creating or editing a pipeline.

The intrusion began with Storm-3068 gaining access to a user account through a self-service password reset process and then taking full control of the identity by registering its own authentication methods.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

Using Azure DevOps audit logs and Git version history, investigators reconstructed the next stage of the intrusion.

Microsoft Defender Experts (DART) 2026-09-29

Builds on: Storm-2949 SSPR-to-Key-Vault Azure kill chain · A public tool automates bulk enumeration of Entra ID accounts, their MFA methods and their…

threat30 Sep 04:43Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cdn-dynmedia-1.microsoft.com1 (50%)
  • microsoft.com1 (50%)