Description

The threat actor known as JADEPUFFER, tracked by Microsoft as Storm-3168, has been observed carrying out destructive operations in a Microsoft Azure environment using compromised service principals. The activity occurred in early June 2026 and lasted approximately 18 hours. The attackers targeted a wide range of Azure resources, including Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, App Services, and recovery protection mechanisms. Microsoft described the campaign as an evolution in the actor’s tradecraft and assessed that its ultimate objective was aligned with ransomware. The attack involved two compromised service principals within the same tenant. One was primarily used for reconnaissance and resource discovery, conducting more than 300 read operations over nearly 16 hours. The second service principal later performed additional discovery before launching destructive and credential-collection activities. In a 35-minute period, it carried out more than 150 such operations, while the main destructive sequence lasted around seven minutes and included more than 100 attempts to delete storage accounts. Most targeted storage accounts were successfully deleted, although resource locks and deletion protections prevented some deletions. Microsoft said the compromised credentials may have originated from a public GitHub issue where an employee had inadvertently exposed the service principal’s client ID, client secret, and tenant ID. Although the secret was later removed, it remained accessible through GitHub’s edit history. The incident highlights the risks of exposed cloud credentials and excessive identity permissions. Notably, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version, providing an additional layer of protection. JADEPUFFER was previously documented by Sysdig in connection with an LLM-assisted ransomware operation that exploited a Langflow vulnerability, harvested credentials, moved laterally, and encrypted AI-related infrastructure. Microsoft has since observed repeated probing of Azure App Services associated with Storm-3168 infrastructure, suggesting automated or scripted activity. No ransom note or successful data exfiltration was observed in this Azure incident, but the deletion of recovery-related resources indicates an attempt to hinder restoration. The campaign demonstrates how AI-assisted or automated workflows can accelerate destructive cloud attacks and underscores the importance of strong identity controls, secret management, resource locks, and independent recovery safeguards.