Critical Azure DevOps and Kubernetes Flaw Exposes Cloud Environments
Key Takeaways A single compromised account can lead to extensive cloud environment breaches, including Azure DevOps and Kubernetes resources. The attack, attributed to Storm-3068, leveraged...
Key Takeaways
- A single compromised account can lead to extensive cloud environment breaches, including Azure DevOps and Kubernetes resources.
- The attack, attributed to Storm-3068, leveraged legitimate administrative tools and existing access rights rather than exploiting software vulnerabilities or custom malware.
- Initial access was gained through a self-service password reset, followed by the attacker registering their own authentication methods for persistent access.
- The incident highlights the critical importance of securing development pipelines and cloud environments, as they can provide a direct path to sensitive data and infrastructure.
- Organizations must implement robust security measures, including phishing-resistant MFA, least-privilege access, and stringent code review processes.
A recent security incident has brought to light a critical vulnerability in cloud environments, demonstrating how a single compromised user account can serve as a gateway to an organization’s entire cloud infrastructure, encompassing Azure DevOps, development pipelines, and Kubernetes resources. This sophisticated attack did not rely on novel software flaws or bespoke malware but instead exploited the inherent trust within an organization’s everyday services and existing access rights.
Table Of Content
Investigators uncovered a method where an attacker moved from a simple password recovery process to gaining deep access into critical development and operational systems. This path allowed the intruder to access source code, deployment configurations, and infrastructure credentials, effectively turning routine access into a major breach.
Microsoft’s security analysts, who identified the threat actor as Storm-3068, determined that the initial compromise stemmed from the takeover of an account via a self-service password reset. According to Microsoft in a report, the attacker solidified their foothold by registering their own authentication methods, thereby securing persistent access to the compromised identity.
This incident underscores the increasing attractiveness of development systems as targets for cyber adversaries. Similar attacks, though involving different threat actors, have previously abused legitimate cloud features within Microsoft Entra ID accounts. In this specific case, the interconnected nature of repositories, automation pipelines, and various cloud resources significantly amplified the impact of the initial account compromise.
Hackers Turn One Compromised Account Into Access
Upon successfully compromising the initial account, Storm-3068 proceeded to utilize legitimate administrative tools and automated scripts to meticulously examine Azure DevOps projects, repositories, pipelines, and deployment environments. This reconnaissance phase was crucial for the intruder to understand the interconnectedness of systems and identify locations where valuable credentials might reside. Azure DevOps proved particularly useful due to its integrated nature, bridging software development and cloud operations.
Unlike other incidents, such as a separate Azure DevOps MCP flaw that exploited specific vulnerabilities, this intrusion leveraged an account’s existing permissions. The attacker systematically mapped trusted deployment paths and connected resources, effectively exploiting the organization’s own architecture.
Following the reconnaissance, the threat actor engineered a malicious pipeline designed for large-scale collection of Kubernetes credentials. This involved deploying a kube agent and executing multiple jobs aimed at extracting cluster configuration files. These files contained vital connection details and authentication information necessary to access targeted Kubernetes resources, as detailed in the investigation report. Microsoft confirmed that the attacker deployed a pipeline capable of accessing over 50 resources and authenticating to various services. Ultimately, seven stolen cluster configuration files were found to have been added to a repository, providing the necessary credentials to access the targeted Kubernetes clusters.
This sequence of events illustrates that development platforms can expose far more than just source code. Repositories, service connections, and deployment settings effectively create a detailed roadmap into an organization’s broader IT environment. This allows an attacker to broaden their access by exploiting trusted relationships already established within the business, as highlighted by Microsoft.
Cloud Access
Beyond credential harvesting, Storm-3068 further escalated its access by modifying pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. Investigators concluded these actions were aimed at establishing alternative remote-access channels and exposing the Kubernetes API server for potential direct interaction with the clusters, according to Microsoft.
Chisel commands were used to create a reverse tunnel to an external IP address, though the specific address was not disclosed in the provided information. The detailed intrusion was meticulously reconstructed through an analysis of Azure DevOps audit logs and Git version history, which also helped identify the stolen credentials deposited in the repository, as documented in the <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8914cb25-f2e-471c-b190-86fa64e15983/Hackers-Turn-One-Compromised-Account-Into-Access-to-Azure-DevOps-and-Kubernetes.pdf?AWSAccessKeyId=ASIA2F3EMEYEZJDBJDDK&Signature=DM0cLQ63WF0RAe6uoG2Rbt5m2bM%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBhfy4xvDSD8ElqcIZNVEC14oU%2FkfCrVpiOpw8DxlBxYAiEA4b5SdTh%2B72%2FyZ1dVtpgx%2FVcECJHsJ00%2B3qeLO%2BLeZl8q%2BgQIYxABGgw2OTk3NTMzMDk3MDUiDA%2B%2BxvbVySrfZpyXTSrXBKhLNmGGjklZ8l%2BN7ffBVt0i0md5xtRr119vCjz5xvkxkqtZHYtjwh%2FgwbKRvcShJeWN%2Big0ldWJGSQt2x8eqIBcE1Xcoe6LcsrEwUM81KRIf2OApUTaun1agQP1rgXtYBq29z2Ui78dICaaCDTfZM7hElCbCz8ypKiLSRs9fMgLHpPn37lrLmuQQKVGs37O949GjAnhDkMNMVAskfVf%2F8x5IBgfIIYSmeDWN0v7uzZT3ZapFYCLBWw7XUvx%2BeLdrXD8Y5OY0yWC8ocwMur94a4WuGpEUilzzsaS84k7fRNdyElUiTlq3TsVkgy3rtL31GZbMSiD6xhYI1RnELSeYOe02PUE6YxPpZugIZkU8RG121qtejnjw5a3dooa3UqzXLuFyk5thtcTMt6LkAFGife0I%2BNZIFsbKmCQGFLsnSyv2GDrzTWFSz%2Bx59QKJ%2BlGG1E0cXbVSDcNWgYIHBo1IMWy57riYfkWjJ3PiYRZA2wyHu6Hk8GWjK7eGt6yf2D%2BNdI6ZYTZFgobTPa58EAoAFHgyup9tQpfvWSKQP8K2jBOaOClfCZV8xVi531KOHk%2FwZD4Zgk8ybFOg5F9YUIFKJc0UdakOWN6zzNq5g9Y%2BlCXWT%2Fa50yKuT%2BZbA%2FsThmhESx3q7Iu4Z3Jlv%2FC9eAd0F9lXqaQrOv2
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.