The exploitation of a self-service password reset workflow enabled attackers to gain control over a standard user account and move laterally through Azure DevOps environments. This specific maneuver marks a significant shift in adversary behavior, where the focus has moved from unearthing zero-day vulnerabilities to exploiting the inherent trust within identity management systems. By infiltrating a single standard account, threat actors can bypass traditional network perimeters that were once considered the primary defense of the enterprise. In the current landscape of 2026, the reliance on cloud-native services has inadvertently created a new attack surface where the user identity serves as the ultimate key to the kingdom. Threat groups such as Storm-3068 have mastered the art of “living-off-the-cloud,” a strategy that eschews custom malware in favor of legitimate administrative tools. This method allows intruders to remain nearly invisible by blending their malicious activities with the routine operations of a high-functioning IT department.
From Initial Access to Persistent Control
The Initial Breach: Exploiting Identity and Establishing a Foothold
The journey of a cloud breach often starts at the most vulnerable point of entry: the self-service password reset (SSPR) mechanism. When an organization fails to strictly govern these workflows, an attacker can identify a susceptible account and reset its credentials without ever needing to know the original password. Once the password is changed, the attacker does not simply stop there; they immediately move to solidify their presence by registering their own multi-factor authentication (MFA) methods. This strategic maneuver, frequently referred to as identity hijacking, ensures that the intruder retains access even if the legitimate user notices a problem and attempts to change their password again. By embedding their own security tokens into the account’s profile, the adversary transforms a temporary login into a persistent gateway. This approach circumvents the standard behavioral analytics that typically flag multiple failed login attempts or brute-force attacks.
Internal Mapping: Mapping the Environment and Weaponizing Service Connections
Once the identity is firmly under the attacker’s control, the focus shifts toward the heart of the organization’s development engine: Azure DevOps. This platform serves as the central nervous system for modern software development, connecting raw source code to automated build pipelines and, eventually, to production cloud environments. The attacker utilizes legitimate discovery scripts and administrative tools to map out the digital estate, identifying every repository, project, and deployment environment available to the compromised account. This internal mapping process provides a comprehensive blueprint of the organization’s cloud architecture, highlighting where the most valuable data is stored and how it is protected. The most critical targets are “service connections,” which are the authorized pathways that allow pipelines to deploy code directly into cloud resources like Kubernetes. By hijacking these connections, the threat actor can bypass the checks that govern human access to production.
Executing the Cloud Intrusion
Core Infrastructure Impact: Scaled Resource Access and Kubernetes Exploitation
With a firm grasp of the service connections available, the attacker proceeds to create or modify existing build pipelines to serve their malicious ends. Because the compromised account often holds sufficient permissions within specific projects, the actor can authorize a pipeline to interact with a vast array of organizational resources simultaneously. This horizontal expansion allows the threat actor to collect data and configuration details from across the entire enterprise in a matter of minutes. The technical culmination involving the specific targeting of Kubernetes clusters is particularly devastating. By deploying specialized agents, the attacker executes automated jobs designed to harvest Kubernetes configuration files, known as kubeconfigs. These files are the equivalent of a master key for the cluster, containing authentication tokens and connection details. The exfiltration of these configuration files represents a total compromise of the production infrastructure, allowing the intruder to interact with the API directly.
Persistence Tactics: Installing Backdoors and Bypassing Network Restrictions
To ensure they were not easily evicted from the environment, the threat actor implemented a layered approach to persistence by installing secondary remote management tools and specialized utilities. These tools, such as the Atera agent, provided a redundant backchannel into the network that remained active even if the original compromised identity was disabled. Furthermore, the attacker deployed tunneling utilities like Chisel to create secure, encrypted reverse tunnels between the internal cloud environment and their own external infrastructure. These tunnels were designed to bypass firewall restrictions by encapsulating traffic within common protocols. The incident highlighted that identity had truly become the new perimeter. Organizations realized that hardening the software development life cycle was just as important as securing the final product. Moving forward, the adoption of phishing-resistant MFA and the implementation of strict manual approval gates for all pipeline changes became standard practice.
