2 Sources
[1]
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The
[2]
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the
Share
Copy Link
Microsoft revealed that JADEPUFFER, tracked as Storm-3168, orchestrated destructive attacks on Azure environments using compromised service principals. The threat actor deleted over 100 Azure Storage accounts, Key Vaults, and databases in just seven minutes during an 18-hour operation in June 2026, marking a significant evolution in AI-driven ransomware tactics.
The ransomware operator known as JADEPUFFER executed a destructive campaign against Microsoft Azure environments in early June 2026, using compromised service principals to systematically delete critical cloud resources
1
. Microsoft Security Research, tracking this activity under the designation Storm-3168, documented an 18-hour operation that culminated in a seven-minute deletion spree targeting more than 100 Azure Storage accounts2
. The attack represents a troubling evolution in AI-driven attacks, where autonomous agents orchestrate complete ransomware operations from initial breach to data destruction.
Source: Hacker News
Storm-3168 leveraged two compromised service principals linked to the same Azure tenant, dividing operational responsibilities between reconnaissance and destruction
1
. The first service principal conducted extensive enumeration activities for nearly 16 hours, executing over 300 read operations to map Azure Virtual Machines, subscriptions, resource groups, and resources. The second service principal joined 90 minutes later, rapidly enumerating virtual machines and resource groups across two subscriptions within five seconds1
. This operational division suggests either automated scripting or carefully coordinated manual oversight, with each identity serving distinct tactical purposes.Microsoft investigators discovered that credentials for one service principal had been exposed in plaintext within a public GitHub issue by an employee of the targeted organization
1
. Although the secret was subsequently removed, it remained accessible through the repository's public edit history, providing JADEPUFFER with the access credentials needed to authenticate as legitimate Azure services.After 16 hours of reconnaissance, the second service principal initiated a concentrated assault, performing more than 150 destructive or credential collection operations within 35 minutes
1
. The destructive sequence specifically targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services1
. Most Azure Storage accounts were successfully deleted, though Azure resource locks and storage account-level deletion protection blocked some attempts, demonstrating the value of independent safeguards that remain effective even when compromised identities possess broad administrative permissions1
.Attempts to delete Azure SQL databases failed due to the threat actor using an unsupported API version for the database resource type
1
. The parallel targeting of databases and Azure Storage accounts suggests an effort to maximize destructive impact across different data services rather than concentrating on a single resource type2
. Roughly 30 minutes after the deletion attempts, Storm-3168 returned to execute more than 30 requests for storage account keys, with most succeeding2
.Related Stories
JADEPUFFER first emerged in July as what Sysdig described as the first ransomware operation run end-to-end with the help of a large language model
1
. The initial attack exploited a known security flaw in Langflow (CVE-2025-3248) to gain entry, then harvested credentials, conducted lateral movement through the network, encrypted Nacos service configuration files, dropped database tables, and left ransom notes demanding Bitcoin payment1
. The autonomous agent reasoned about targets, reused credentials, established persistence, and destroyed databases while narrating its own intent throughout the operation1
.
Source: BleepingComputer
The same Langflow instance was subsequently targeted a second time using ENCFORGE, a compiled Go-based ransomware strain specifically designed for AI infrastructure
1
. ENCFORGE scans for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files including Keychain stores, Xcode project files, and Apple Pages and Numbers documents1
. This specialization indicates JADEPUFFER is deliberately targeting organizations with valuable AI assets and intellectual property.Microsoft detected repeated probing from Storm-3168 linked infrastructure against several Azure App Services for different customers, suggesting these attacks are likely automated or scripted
1
. The end goal appears ransomware-aligned, given the deletion of numerous Azure resources alongside backup and recovery-related resources, indicating efforts to impair victims' ability to recover from destructive activity1
. However, no ransom note or confirmed data exfiltration was observed in connection with the June intrusion1
.The threat actor's removal of Azure Site Recovery locks demonstrates sophisticated understanding of cloud backup mechanisms and deliberate attempts to make restoration more difficult
2
. This operational pattern could support future ransomware extortion, though Microsoft has not confirmed financial demands in observed cases2
. Organizations should activate cloud workload protections, audit public repositories for exposed secrets, evaluate Azure RBAC permissions against least-privilege principles, and implement resource locks on critical assets2
. The activity highlights a broader shift toward AI-orchestrated cyber threats where autonomous agents can execute complete attack chains with minimal human intervention.Summarized by
Navi
[1]
[2]
21 Jul 2026•Technology

01 Jul 2026•Technology

10 Sept 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
