2026-09-30NOTABLEMicrosoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials
Storm-3068
actor · actor:storm-3068 single-source
Microsoft designator for an actor that turned a successful self-service password reset into Azure DevOps pipeline abuse, Atera and Chisel tooling and stolen Kubernetes credentials; Microsoft gives no attribution, victim or date (Microsoft Defender Experts, 2026-09-29).
Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Microsoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Defender insights
What each entry about Storm-3068 tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (8 across 9 tactics)
8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Cloud Accounts
- ExecutionSoftware Deployment Tools
- PersistenceValid Accounts: Cloud Accounts · Account Manipulation: Device Registration
- Privilege EscalationValid Accounts: Cloud Accounts · Account Manipulation: Device Registration
- StealthValid Accounts: Cloud Accounts
- Credential AccessUnsecured Credentials: Credentials In Files
- Lateral MovementSoftware Deployment Tools
- CollectionData from Information Repositories: Code Repositories
- Command and ControlIngress Tool Transfer · Remote Access Tools · Protocol Tunneling
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Execution TA0002
T1072Software Deployment Tools×1
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Lateral Movement TA0008
T1072Software Deployment Tools×1
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Collection TA0009
T1213.003Data from Information Repositories: Code Repositories×1
Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft · ATT&CK page ↗
Entries about Storm-3068 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cdn-dynmedia-1.microsoft.com1 (50%)
- microsoft.com1 (50%)
All cited sources (2)
- cdn-dynmedia-1.microsoft.comMicrosoft Defender Experts (DART), Cyberattack Series report Q3 2026https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/bade/documents/products-and-services/en-us/security/Cyberattacks-Series-Report-Q3-2026.pdf
- microsoft.comMicrosoft Defender Experts (DART)https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/