Storm-3068 Exploited Password Reset to Steal Kubernetes Credentials via Azure DevOps
Microsoft Defender Experts have documented a critical attack by threat group Storm-3068, in which attackers hijacked a user account by completing a self-service password reset (SSPR) and registering an attacker-controlled device in Microsoft Intune. The actor then removed the legitimate user's MFA method and substituted their own, securing persistent control over the compromised identity. Using valid credentials, Storm-3068 accessed Azure DevOps, enumerated repositories, pipelines, and connected resources, then executed a pipeline authorized to reach more than 50 resources to extract kubeconfig files containing Kubernetes ServiceAccount tokens. Seven kubeconfig files were reportedly added to an existing repository, with the stolen tokens enabling potential authentication to Kubernetes APIs. The attackers also deployed the Atera remote management agent and ran the Chisel tunneling tool in an attempt to establish a persistent external reverse proxy, though the full extent of successful tunnel connections has not been publicly confirmed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in