Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources
Microsoft says Storm-3168 used compromised Azure service principals to delete cloud resources and collect storage keys.
Microsoft reported a destructive Azure campaign by Storm-3168, also known as JADEPUFFER, that abused two compromised service principals in one tenant. One identity spent about 15.5 hours on more than 300 read operations, enumerating virtual machines, subscriptions, and resource groups. A second identity then attempted more than 150 destructive or credential actions in roughly 35 minutes, deleting most targeted storage accounts plus a Key Vault, Function App, and App Service plan, and trying to strip backup and Site Recovery locks. About 30 minutes later it made more than 30 successful ListKeys calls; Microsoft saw no ransom note or confirmed theft, but said the pattern fits extortion, and the credentials had been published in a public GitHub issue.