VYPR
breachPublished Sep 28, 2026· 1 source

JadePuffer Actor Leverages Hijacked Azure Identities for Destructive Cloud Attacks

The threat actor Storm-3168, linked to the agentic ransomware JadePuffer, has been observed hijacking Azure service principals to conduct destructive attacks and steal credentials within cloud environments.

Microsoft has revealed that the threat actor Storm-3168, associated with the agentic ransomware JadePuffer, has engaged in destructive attacks against cloud resources by compromising Azure service principals. This actor, previously identified for its use of an AI-driven ransomware operation, has now demonstrated a capability for extensive damage and credential harvesting within cloud tenants.

Over an 18-hour period in early June, Storm-3168 successfully compromised two service principals within the same Azure tenant. Researchers noted that one of these compromised identities was used for reconnaissance and discovery of Azure resources, while the second was employed for destructive operations and the collection of cloud credentials. The exact method of initial compromise for these service principals remains unknown, though Microsoft pointed to a prior incident where an employee inadvertently exposed sensitive credentials like client IDs and secrets in a public GitHub repository.

The attack involved extensive reconnaissance, with the first compromised service principal performing over 300 read operations across various Azure resources, including Virtual Machines, subscriptions, and resource groups. This provided the attacker with a comprehensive view of the victim's cloud environment. Approximately 90 minutes later, the second service principal began its operations, quickly accessing information across two subscriptions, indicating a coordinated and efficient attack.

Following the discovery phase, the attacker initiated destructive actions. The compromised service principal attempted over 150 destructive or credential-stealing operations within a 35-minute window. This included the deletion of more than 100 Azure Storage accounts, an Azure Key Vault, and a Function App. While some deletion attempts were blocked by resource locks, a significant number were successful, indicating a substantial impact on the victim's infrastructure.

Further attempts were made to delete Azure SQL databases, though these failed due to the use of an unsupported API version. The attacker also focused on credential harvesting, making over 30 successful ListKeys requests to obtain access keys for Azure Storage Accounts, including those related to Azure Site Recovery. Attempts were also made to interfere with backup and recovery mechanisms by targeting related locks.

Microsoft's analysis suggests that the combination of resource destruction, interference with recovery systems, and credential collection aligns with tactics used to support ransomware and extortion operations. The targeting of storage accounts and backup resources could be an attempt to cripple recovery capabilities before data exfiltration or encryption. However, no ransom note was observed, and successful data exfiltration was not confirmed in this specific incident.

The broader implications of this attack highlight the growing sophistication of cloud-native threats. The use of compromised machine identities like service principals bypasses traditional user-based authentication controls, making detection more challenging. The actor's ability to perform both reconnaissance and destructive actions underscores the need for robust cloud security posture management and identity and access management (IAM) best practices.

This incident also draws attention to the evolving tactics of threat actors like Storm-3168, who are leveraging advanced techniques, including AI-driven ransomware and now sophisticated cloud exploitation, to maximize impact and disruption. Organizations utilizing cloud platforms must remain vigilant against these evolving threats and implement comprehensive security measures to protect their cloud assets.

Synthesized by Vypr AI
JadePuffer Actor Leverages Hijacked Azure Identities for Destructive Cloud Attacks · VYPR