Threat · curated 28 Sep 2026

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Dossier

Coverage timeline

28 Sep 2026thehackernews.comdarkreading.combleepingcomputer.comtheregister.com

Why it matters

JADEPUFFER's agentic-driven, service-principal-based destruction of Azure resources shows AI-agent-enabled attackers can rapidly and irreversibly wipe cloud infrastructure, raising the stakes for identity and cloud defenders.

The threat actor JADEPUFFER, tracked by Microsoft as Storm-3168, carried out destructive operations in a Microsoft Azure environment over roughly 18 hours in early June 2026 by compromising service principals to target Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. Microsoft characterizes the campaign as agentic-driven cloud attacks and an evolution of the actor's tradecraft, having previously documented JADEPUFFER exploiting a Langflow RCE to deploy an AI agent.

campaign

Summary

The threat actor JADEPUFFER, tracked by Microsoft as Storm-3168, orchestrated destructive operations inside a Microsoft Azure environment using compromised service principals over a roughly 18-hour period in early June 2026. Microsoft characterized the activity as an evolution of the actor's tradecraft, targeting Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services.[0][11]

The attack leveraged two compromised service principals in the same tenant, one for reconnaissance and resource discovery (over 300 read operations across ~16 hours) and a second for over 150 destructive or credential-collection operations in 35 minutes, including more than 100 storage account deletion attempts within a ~7 minute destructive burst. Microsoft assessed the goal as ransomware-aligned, aimed at deleting backup and recovery resources to impair recovery, though no ransom note or successful exfiltration was observed.[0]

Independent safeguards mattered: Azure resource locks and storage account-level deletion protection blocked some deletions, and Azure SQL database deletions failed due to an unsupported API version. Microsoft assessed the operations as likely automated or scripted and part of a broader shift toward AI-orchestrated cloud attacks.[0]

Attack chain

  1. Initial access via exposed credentials: A service principal's client ID, client secret, and tenant ID had been exposed in plaintext in a public GitHub issue by an employee of the impacted organization; although the secret was removed, it remained accessible via the public edit history. The exact method of compromise remains unclear.[0]
  2. Reconnaissance and resource discovery: The first compromised service principal enumerated Azure Virtual Machines, subscriptions, resource groups, and resources for close to 16 hours, performing over 300 read operations. A second service principal performed its own rapid discovery 90 minutes later, enumerating VMs and resource groups across two subscriptions within five seconds.[0]
  3. Credential collection: After roughly 16 hours, the second service principal enumerated Azure App Service configuration stores, likely to look for exposed credentials, then conducted more than 150 destructive or credential-collection operations in 35 minutes.[0]
  4. Destructive impact: The destructive sequence lasted about seven minutes and included over 100 storage account deletion attempts, plus targeting of an Azure Key Vault, Function App, App Service plan, and multiple Azure SQL databases. Most storage accounts were deleted, while resource locks/deletion protection and an unsupported SQL API version blocked others.[0]

Disclosure timeline

DateEvent
Early June 2026The Storm-3168/JADEPUFFER destructive Azure operation took place over about an 18-hour period.[0]
September 25, 2026Microsoft published its analysis of Storm-3168's agentic-driven cloud attacks using compromised service principals.[0][11]
September 28, 2026The Hacker News reported on the Microsoft findings.[0]

Actor profile

JADEPUFFER (Microsoft: Storm-3168)

JADEPUFFER was first documented by Sysdig as the first ransomware operation run end-to-end with the help of an LLM, having exploited CVE-2025-3248 in Langflow to harvest credentials, move laterally, encrypt Nacos configuration files, and leave a Bitcoin ransom note. Microsoft tracks the actor as Storm-3168 and assesses the Azure campaign as an evolution of its tradecraft, likely automated or scripted given the division of work across multiple service principals. Microsoft also detected repeated probing from Storm-3168-linked infrastructure against multiple customers' Azure App Services. The activity is assessed as ransomware-aligned.[0][11]

How it works

The core enabling weakness was credential exposure rather than a software vulnerability: a service principal's client ID, client secret, and tenant ID were leaked in plaintext in a public GitHub issue, and remained retrievable through the issue's public edit history even after the secret was deleted. This granted attackers valid identity credentials with broad administrative permissions.[0]

Destructive actions were bounded by independent Azure safeguards: resource locks and storage account-level deletion protection prevented deletion of some storage accounts despite the compromised identity's broad permissions, and Azure SQL database deletion attempts failed because the attacker used an unsupported API version for the Azure SQL database resource type.[0]

The original JADEPUFFER intrusions documented by Sysdig exploited CVE-2025-3248, a known Langflow flaw, for initial access, and used MySQL's built-in AES_ENCRYPT() function for encryption; a follow-on strain, ENCFORGE, is a Go-based ransomware built for AI infrastructure that scans for nearly 180 file extensions including model checkpoints, vector databases, and training datasets.[0][30]

Affected versions and patch status

ProductAffectedPatch status
Microsoft Azure (tenant with compromised service principals)Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services within the impacted tenantNo product patch; impact mitigated by resource locks, storage account-level deletion protection, and API version constraints. Not a product-level vulnerability.[0]
Langflow (original JADEPUFFER intrusions)CVE-2025-3248 exploited for initial access in earlier JADEPUFFER activityCVE referenced; not the vector for the Azure destructive campaign described here.[0][30]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2025-3248Langflow flaw exploited by JADEPUFFER in earlier documented intrusions for initial access; relevant to defenders tracking the actor's broader operations.[0][30]

Key takeaways

  • Leaked service principal credentials, even briefly exposed and then deleted, remain a viable initial access path because of retained public edit history; secret rotation must follow any exposure.[0]
  • Independent Azure safeguards such as resource locks, storage account deletion protection, and API version constraints materially limited destructive impact even when the attacker held broad administrative permissions.[0]
  • The campaign reflects a broader shift toward AI-orchestrated, automated post-compromise cloud operations that coordinate reconnaissance and destruction with greater speed and scale.[0]

Defensive actions

  • Enable Azure resource locks and storage account-level deletion protection on critical resources.: These independent safeguards blocked deletion attempts for some storage accounts even though the compromised identity held broad administrative permissions, demonstrating their value against destructive operations.[0]
  • Scan public code repositories and issue trackers for exposed service principal credentials and rotate any leaked secrets, accounting for edit history.: The compromised service principal's client ID, client secret, and tenant ID were leaked in plaintext in a public GitHub issue and remained accessible through the public edit history even after the secret was removed.[0]
  • Monitor service principals for anomalous, high-volume enumeration and rapid destructive API activity across subscriptions.: The attack showed distinctive patterns: over 300 read operations across ~16 hours, enumeration of VMs and resource groups across subscriptions in five seconds, and 150+ destructive/credential operations in 35 minutes, consistent with automated or scripted activity.[0]
  • Watch for probing from Storm-3168-linked infrastructure against Azure App Services.: Microsoft detected repeated probing from Storm-3168-linked infrastructure against several Azure App Services across different customers.[0]