Storm-3068 hijacked account via SSPR and stole Kubernetes credentials
Microsoft Defender Experts detailed an attack by Storm-3068: a self-service password reset (SSPR) let the actor take over a user identity, register an attacker device in Intune and add their own MFA while removing the victim's. Via Azure DevOps they ran a pipeline authorized for 50+ resources, pulled 7 kubeconfig files and deployed the Atera agent and a Chisel tunnel.
- SSPR on a user account led to full account takeover in Entra ID
- Attacker added a new MFA method, removed the victim's and enrolled a device in Intune
- Pipeline authorized for 50+ resources dumped 7 kubeconfig files with ServiceAccount tokens
- Atera agent deployed and Chisel executed via pipeline for a reverse tunnel
Read next
Security