MICROSOFT’S Cyberattack Series examines a case where a single compromised identity cascaded through an organisation’s development and cloud environments. Storm-3068 gained initial access by abusing a self-service password reset, registering its own authentication methods, and then used legitimate administrator tools to map Azure DevOps projects, pipelines, and deployment environments.
Rather than deploying malware, the attacker exploited trusted pipelines to harvest Kubernetes credentials at scale, deploying a kube agent and altering scripts to exfiltrate kubeconfig files and expand access to more than 50 resources.
Investigators found evidence of a malicious pipeline designed to grab Kubernetes credentials and to install the Atera remote management agent and the Chisel tunneling utility, with Chisel commands used to establish a reverse tunnel to an external IP address in order to enable prospective remote interaction with the Kubernetes API server. The result was a path from a compromised identity into connected cloud infrastructure and production resources.
The Microsoft Detection and Response Team (DART) responded rapidly, tracing activity across identity systems, development platforms and cloud services, and disrupted the actor’s access while coordinating with the customer and Microsoft Threat Intelligence. The report emphasises that Azure DevOps can reveal far more than source code—repositories, pipelines, service connections and deployment settings can map an organisation’s broader environment.
Defence recommendations focus on monitoring unusual password-reset activity, strengthening protection for privileged accounts (including phishing-resistant MFA), tightening code-change approvals and branch protection, restricting pipeline permissions, and applying least-privilege access across identities, DevOps, and cloud resources to limit future risk. The full Cyberattack Series report is available for deeper detail.