Attackers Exploit Azure DevOps to Exfiltrate Kubernetes Secrets After Account Compromise
Microsoft disclosed that the threat group known as Storm-3068 leveraged a hijacked user account to commandeer Azure DevOps pipelines, ultimately extracting Kubernetes authentication material and opening pathways into linked cloud workloads.
The intrusion began with the adversaries obtaining legitimate credentials for a developer‑level account. Once inside, they repurposed existing build and release pipelines, embedding custom scripts that invoked Azure CLI commands to enumerate service connections and retrieve stored secrets.
By manipulating the pipeline’s execution environment, the attackers were able to download the cluster's kubeconfig files and token credentials from Azure Key Vault references embedded in the DevOps project. Those files grant full administrative access to the targeted Kubernetes clusters, enabling the threat actors to execute commands, deploy containers, or pivot to other services within the same subscription.
Security analysts warned that possession of these Kubernetes credentials could allow the group to harvest data, disrupt workloads, or establish persistent footholds for further exploitation. Because Azure DevOps integrates tightly with other Azure resources, the breach has the potential to cascade across multiple environments if the stolen tokens are not revoked promptly.
In response, Microsoft urged customers to enforce multi‑factor authentication, adopt least‑privilege principles for service accounts, and rotate any secrets that may have been accessed. The company also recommended enabling pipeline‑level audit logging and employing anomaly‑detection tools to flag unusual script executions or outbound network traffic from build agents.
The incident underscores a growing trend where attackers target software‑supply‑chain components rather than directly assaulting production systems. DevOps platforms such as Azure DevOps, GitHub Actions, and GitLab CI have become attractive vectors because they often hold elevated permissions and can automate credential distribution.
Enterprises are expected to review their CI/CD security posture, implement stricter access controls, and consider segmentation between development and production resources. Ongoing investigations by Microsoft and independent security researchers aim to map the full scope of the campaign and identify any additional compromised accounts across the affected tenant.
Comments (0)
Be the first to comment.
Join the discussion