Description

JADEPUFFER, also tracked by Microsoft as Storm-3168, has been linked to a destructive cyberattack against a Microsoft Azure environment in June 2026. The incident lasted roughly 18 hours and demonstrated how compromised cloud identities can be abused to conduct reconnaissance, steal credentials, and damage critical infrastructure. According to Microsoft’s investigation, attackers gained access to two service principals belonging to the same Azure tenant. One identity was primarily used to explore the environment, while the second was later used for additional discovery, credential searches, and destructive activity. During nearly 16 hours of reconnaissance, the attackers performed more than 300 read operations involving virtual machines, subscriptions, resource groups, and other Azure resources. The attackers subsequently examined Azure App Service configuration data, apparently searching for credentials that could provide further access. Shortly afterward, they launched a concentrated destructive campaign lasting approximately seven minutes. More than 100 attempts were made to delete Azure Storage accounts, with many of the deletions succeeding. Azure Key Vaults, Function Apps, App Service resources, SQL databases, and recovery-related protections were also targeted. Some defensive controls prevented additional damage. Resource locks and storage-level deletion protections stopped the removal of several storage accounts. Attempts to delete Azure SQL databases also failed because the attackers used an API version that was not supported for the targeted resource type. Microsoft determined that the compromised service principal credentials had previously been exposed in a public GitHub issue. Although the secret was later removed, it remained available through the issue’s edit history, illustrating the risks associated with accidentally publishing cloud credentials. JADEPUFFER had previously been associated with an AI-assisted ransomware campaign that exploited a Langflow vulnerability. Its activity demonstrates an emerging pattern in which attackers can use automation and AI-enabled tooling to coordinate reconnaissance, credential collection, lateral movement, and destructive operations. Microsoft assessed the Azure incident as ransomware-aligned, although no ransom note or confirmed data theft was identified.