Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details Storm-3168 (JADEPUFFER) destroying Azure resources via compromised service principals in the first documented agentic ransomware operation's Azure activity.
Microsoft tracks JADEPUFFER, discovered by Sysdig in July 2026 as the first documented agentic ransomware operation, as Storm-3168. In one tenant, two compromised service principals performed 300+ read operations over 15.5 hours of Azure reconnaissance, then executed a 7-minute destructive sequence including 100+ storage account deletion attempts, plus deletion of an Azure Key Vault, Function App, and App Service plan. The actor then sent 30+ successful ListKeys requests to collect storage account access keys; initial access may have come from a service principal secret exposed in a public GitHub issue's edit history. Azure resource locks and deletion protection blocked some destruction, showing the value of independent safeguards.