Storm-3068: a successful self-service password reset became Azure DevOps pipeline abuse and stolen Kubernetes credentials, with no malware or exploit
Microsoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials
Analysis
Microsoft's Defender Experts incident-response team (DART) describes a malware-free, exploit-free intrusion by the actor it designates Storm-3068 that began when the actor gained access to a user account through a self-service password reset and took full control of the identity by registering its own authentication methods (Microsoft Defender Experts, 2026-09-29). Microsoft does not say how the reset challenge was passed. With that persistent access, the actor used legitimate administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, pipelines and deployment environments, then created a malicious pipeline that deployed a kube agent and ran jobs to collect kubeconfig files; that pipeline inherited the compromised account's permissions and was authorized to access more than 50 resources (Microsoft Defender Experts, 2026-09-29). The actor also modified pipeline scripts to install the Atera remote-management agent and download the Chisel tunneling utility, and ran Chisel to open a reverse tunnel to an external address, which Microsoft describes as an attempt at alternative remote access and at exposing the Kubernetes API server (Microsoft Defender Experts, 2026-09-29). Investigators rebuilt the sequence from Azure DevOps audit logs and Git version history and found seven stolen kubeconfig files committed to a repository (Microsoft Defender Experts, 2026-09-29). The full report adds that the actor registered a new MFA method and deleted the account's legitimate MFA methods, started the kube agent by downloading and running a third-party script with several jobs, saved the kubeconfig files into an existing kubeconfigs folder of the target repository (each holding a cluster API endpoint, certificate-authority data and a service-account token), and expanded access in a matter of hours rather than days (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29).
Where it surfaces: identity-provider audit logs show a completed password reset followed by new authentication-method registrations on the same account (Microsoft Defender Experts, 2026-09-29), and the full report's attack flow adds deletion of the legitimate methods (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29), while Microsoft advises watching for repeated resets or resets against many users; DevOps audit logs show one identity enumerating repositories and pipelines and then creating or modifying pipelines; Git history shows pipeline scripts that install a remote-management agent or download a tunneling tool, and kubeconfig files committed to a repository; build-agent egress shows a reverse tunnel to an external address (Microsoft Defender Experts, 2026-09-29). Microsoft's recommended controls are to keep privileged accounts out of self-service password reset or protect them with phishing-resistant multifactor authentication, enforce branch protection and approvals for code changes, restrict direct commits to critical branches, limit who can create, modify or run pipelines, and apply least privilege across identity, DevOps and cloud (Microsoft Defender Experts, 2026-09-29).
Triage: a user completing a password reset and then registering authentication methods is routine. The sequence that separates this activity is the same identity, right after the reset, enumerating Azure DevOps repositories and pipelines in bulk and then creating or editing a pipeline.
Cited evidence
The intrusion began with Storm-3068 gaining access to a user account through a self-service password reset process and then taking full control of the identity by registering its own authentication methods.
The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.
Using Azure DevOps audit logs and Git version history, investigators reconstructed the next stage of the intrusion.
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.