Microsoft and Unnamed Affected Organization: Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft and Unnamed Affected Organization: Storm-3168: Agentic-driven cloud attacks using compromised service principals

JADEPUFFER: Microsoft Uncovers Destructive Cloud Attack by Storm-3168

In July 2026, Microsoft Security Research exposed JADEPUFFER, a threat actor first documented by Sysdig as the first agentic ransomware operation a sophisticated, AI-driven attack framework targeting cloud environments. Tracked by Microsoft as Storm-3168, the group has evolved its tactics, demonstrating a shift toward automated, large-scale destructive operations in Azure.

The Attack: A Coordinated Cloud Destruction Campaign

In early June 2026, Storm-3168 compromised two Azure service principals within the same tenant, dividing tasks between reconnaissance and destruction/credential theft. Over 15 hours, the first principal conducted 300+ read operations, mapping the victim’s Azure environment including Virtual Machines, subscriptions, resource groups, and storage accounts. The second principal followed, executing a high-speed, scripted attack in under 35 minutes, with a 7-minute destructive sequence targeting:

  • 100+ Azure Storage accounts (most successfully deleted)
  • Azure Key Vaults, Function Apps, and App Service plans (all deleted)
  • Azure SQL databases (deletion failed due to unsupported API version)
  • Backup and recovery protections (Site Recovery locks, Backup protection locks unsuccessfully targeted)

The threat actor also collected storage account access keys, potentially enabling data exfiltration, though no ransom note or confirmed exfiltration was observed. The attack’s parallel targeting of multiple resource types storage, databases, and recovery mechanisms aligns with ransomware objectives, aiming to maximize disruption and impair recovery.

Initial Access: A Preventable Exposure

While the exact compromise vector remains unconfirmed, Microsoft identified a critical misstep: the client ID, client secret, and tenant ID of the compromised service principal were exposed in plaintext in a public GitHub issue by an employee of the affected organization. Though later edited, the credentials remained accessible via the issue’s edit history, underscoring a key risk: publicly exposed secrets remain valid until revoked, regardless of redaction.

Additionally, Storm-3168 had been probing Azure App Services since early 2026, scanning for vulnerable endpoints (e.g., WordPress admin paths, PHP-CGI, LangFlow’s code validation API). However, these probes did not directly lead to the observed breach.

Automation & AI-Driven Tactics

The attack’s precision and speed including overlapping token usage and divided labor between service principals reveal automated execution, likely leveraging AI-driven orchestration. Microsoft observed:

  • Five unique tokens issued for the destructive principal, with two active simultaneously (one for storage deletion, another for mixed SQL/storage attacks).
  • Role-based permissions exploited: Storage Account Contributor (for deletions), Contributor (for app resource deletions), and SQL DB Contributor (for failed database attacks).
  • Selective targeting: A storage account in the same resource group as deleted resources was spared later accessed for key retrieval, suggesting strategic credential harvesting.

Defensive Lessons & MITRE ATT&CK Techniques

The incident highlights critical vulnerabilities in cloud security:

  • Exposed credentials (T1078.004 – Valid Cloud Accounts) enabled the attack.
  • Discovery operations (T1526 – Cloud Service Discovery) mapped the environment before destruction.
  • Data destruction (T1485) and recovery inhibition (T1490) were core objectives.
  • Public-facing app probing (T1190) preceded the breach.

Key Takeaways

Storm-3168’s JADEPUFFER campaign marks a new era of AI-augmented cloud attacks, where threat actors automate complex, multi-stage operations at scale. The incident underscores:

  • The persistent risk of exposed credentials, even after redaction.
  • The effectiveness of Azure resource locks in mitigating damage.
  • The need for least-privilege access and AI-driven defense tools (e.g., Microsoft’s Project Perception, MDASH) to counter automated threats.

While no ransom demand was confirmed, the attack’s destructive intent and credential theft align with extortion-focused tactics, signaling a growing threat to cloud-native environments.

Source: https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

Unnamed Affected Organization TPRM report: https://www.rankiteo.com/company/whitehateu

"id": "micwhi1790396923",
"linkid": "microsoft-security, whitehateu",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization using Azure cloud services'}],
 'attack_vector': 'Exposed credentials in public GitHub issue (client ID, '
                  'client secret, tenant ID)',
 'data_breach': {'data_exfiltration': 'Unconfirmed (potential)',
                 'type_of_data_compromised': 'Storage account access keys '
                                             '(potential data exfiltration)'},
 'date_detected': '2026-06',
 'date_publicly_disclosed': '2026-07',
 'description': 'In July 2026, Microsoft Security Research exposed JADEPUFFER, '
                'a threat actor first documented by Sysdig as the first '
                'agentic ransomware operation—a sophisticated, AI-driven '
                'attack framework targeting cloud environments. Tracked by '
                'Microsoft as Storm-3168, the group evolved its tactics toward '
                'automated, large-scale destructive operations in Azure. The '
                'attack involved compromising two Azure service principals to '
                'conduct reconnaissance and execute a high-speed, scripted '
                'destruction campaign targeting storage accounts, key vaults, '
                'function apps, and backup protections.',
 'impact': {'data_compromised': 'Storage account access keys collected '
                                '(potential data exfiltration)',
            'operational_impact': 'High (destruction of critical cloud '
                                  'resources, impaired recovery mechanisms)',
            'systems_affected': ['Azure Storage accounts (100+ deleted)',
                                 'Azure Key Vaults (deleted)',
                                 'Azure Function Apps (deleted)',
                                 'Azure App Service plans (deleted)',
                                 'Azure SQL databases (deletion failed)',
                                 'Backup and recovery protections (targeted)']},
 'initial_access_broker': {'entry_point': 'Exposed Azure service principal '
                                          'credentials in public GitHub issue',
                           'high_value_targets': ['Storage accounts',
                                                  'Key Vaults',
                                                  'Backup protections'],
                           'reconnaissance_period': 'Early 2026 (probing Azure '
                                                    'App Services)'},
 'investigation_status': 'Ongoing (as of July 2026)',
 'lessons_learned': 'The incident highlights the persistent risk of exposed '
                    'credentials, the effectiveness of Azure resource locks, '
                    'and the need for least-privilege access and AI-driven '
                    'defense tools to counter automated threats.',
 'motivation': 'Disruption, credential theft, potential ransomware/extortion',
 'post_incident_analysis': {'corrective_actions': ['Revoke exposed credentials '
                                                   'and audit all service '
                                                   'principals for public '
                                                   'exposure.',
                                                   'Implement least-privilege '
                                                   'access controls for cloud '
                                                   'resources.',
                                                   'Enable Azure resource '
                                                   'locks for critical '
                                                   'resources.',
                                                   'Enhance monitoring for '
                                                   'automated, AI-driven '
                                                   'attack patterns.'],
                            'root_causes': ['Public exposure of Azure service '
                                            'principal credentials in a GitHub '
                                            'issue (client ID, client secret, '
                                            'tenant ID).',
                                            'Over-permissive roles assigned to '
                                            'service principals (Storage '
                                            'Account Contributor, Contributor, '
                                            'SQL DB Contributor).',
                                            'Lack of Azure resource locks to '
                                            'prevent destructive operations.']},
 'ransomware': {'data_exfiltration': 'Unconfirmed (potential)'},
 'recommendations': ['Revoke exposed credentials immediately, even if redacted '
                     'from public view.',
                     'Implement least-privilege access for cloud resources.',
                     'Use Azure resource locks to mitigate destructive '
                     'operations.',
                     'Deploy AI-driven defense tools (e.g., Microsoft Project '
                     'Perception, MDASH) to detect and counter automated '
                     'attacks.',
                     'Monitor for public exposure of sensitive credentials in '
                     'code repositories and issue trackers.'],
 'references': [{'source': 'Microsoft Security Research'},
                {'source': 'Sysdig (initial documentation of JADEPUFFER)'}],
 'response': {'third_party_assistance': 'Microsoft Security Research'},
 'threat_actor': 'Storm-3168 (JADEPUFFER)',
 'title': 'JADEPUFFER: Microsoft Uncovers Destructive Cloud Attack by '
          'Storm-3168',
 'type': 'Destructive Cloud Attack / Agentic Ransomware',
 'vulnerability_exploited': 'Publicly exposed Azure service principal '
                            'credentials, misconfigured permissions (Storage '
                            'Account Contributor, Contributor, SQL DB '
                            'Contributor)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.