Storm-3168 destroyed Azure resources with stolen principals
Microsoft says Storm-3168 used two compromised Azure service principals to recon, delete resources, and collect storage keys.
Microsoft tracks JADEPUFFER, which Sysdig identified in July 2026 as the first documented agentic ransomware operation, as Storm-3168. In one Azure tenant, two compromised service principals performed more than 300 read operations over about 15.5 hours, enumerating virtual machines, subscriptions, and resource groups. The accounts then describe different time slices rather than one shared clock: a roughly 7-minute destructive sequence with more than 100 storage-account deletion attempts, and more than 150 destructive or credential-collection operations in about 35 minutes, including attempts to strip Azure Backup and Site Recovery locks. Both say a Key Vault, Function App, and App Service plan were targeted, that resource locks and deletion protection stopped some destruction, and that more than 30 successful ListKeys calls collected storage keys, including Site Recovery keys; one report places those calls about 30 minutes after the longer burst. Microsoft reported no ransom note or confirmed theft but said the activity fits extortion. A service-principal secret left in a public GitHub issue’s history is the suspected source; Microsoft says access may have come from it, while the later report states the tenant ID, client ID, and secret had remained there.
- Microsoft tracks JADEPUFFER, identified by Sysdig in July 2026 as the first documented agentic ransomware operation, as Storm-3168.
- In one Azure tenant, two compromised service principals ran more than 300 read operations over about 15.5 hours, enumerating virtual machines, subscriptions, and resource groups.
- Reports give different time slices: a 7-minute destructive sequence with more than 100 storage-account deletion attempts, and about 150 destructive or credential-collection operations in roughly 35 minutes.
- Targets included storage accounts plus an Azure Key Vault, Function App, and App Service plan; attackers also tried to remove Azure Backup and Site Recovery locks.
- Azure resource locks and deletion protection blocked some deletions; most targeted storage accounts were reported deleted.
- More than 30 successful ListKeys calls later returned storage keys, including Site Recovery keys. Microsoft reported no ransom note or confirmed theft but said the pattern fits extortion.
- A service-principal secret remained in a public GitHub issue’s edit history. Microsoft says it may have been the initial-access source; a later report also says the tenant ID and client ID stayed there, and that redaction alone does not…
Coverage timelineoldest first · each row is one article
- · 1d agoStorm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft Security Blog· 78
Microsoft details Storm-3168 (JADEPUFFER) destroying Azure resources via compromised service principals in the first documented agentic ransomware operation's Azure activity.
- · 1d agoStorm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources
GBHackers· 76
Microsoft says Storm-3168 used compromised Azure service principals to delete cloud resources and collect storage keys.