Storm-3168 Threat Actor Exploits Compromised Service Principals for Destructive Azure Attacks

Published:

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. This investigation found extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could facilitate future exfiltration. According to reporting by Microsoft Security Research, these findings expand the publicly documented activity associated with JADEPUFFER, tracked by Microsoft as Storm-3168, demonstrating an evolution in the threat actor’s cloud operations.

Attack Overview

Microsoft observed two compromised service principals belonging to the same tenant. One performed reconnaissance and resource discovery, while the other executed destructive operations and credential collection. In early June 2026, one of the compromised service principals enumerated Azure Virtual Machines, subscriptions, resource groups, and resources for about 15 hours and 30 minutes, conducting over 300 successful read operations. This breadth of activity provided the threat actor visibility across the organization’s Azure environment.

Destructive Sequence

Less than one second after an unsuccessful ListKey operation against a non-existent storage account, the second compromised service principal initiated destructive activities, attempting over 150 destructive or credential collection-related operations in 35 minutes. The destructive sequence lasted about 7 minutes, involving over 100 storage account deletion attempts, most of which were successful. However, Azure resource locks and storage account-level deletion protection blocked some deletion attempts, highlighting the importance of independent safeguards.

Credential Collection and Implications

About 30 minutes after the final destructive activity, the same service principal made an inventory request for Azure Storage Accounts and successfully sent over 30 ListKeys requests, asking ARM to return each storage account’s access keys. This activity indicates a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale.

Microsoft recommends several mitigations to reduce the risk and impact of similar activities, including enabling appropriate Microsoft Defender for Cloud plans, protecting application credentials, and applying least privilege to service principals. Organizations are urged to continuously assess their security posture to defend against evolving threats.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Google Ads Deliver Tech Support Scam Freezing Screens of Windows and Mac Devices

Researchers have uncovered a sophisticated tech support scam being delivered through Google ads, which freeze the screens of both Windows and Mac devices. These...

Microsoft Security Updates Enhance AI Agent Control and Data Protection in September 2026

As artificial intelligence (AI) continues to permeate various aspects of business operations, organizations face new challenges in securing these technologies. In September 2026, Microsoft...

U.S. Soldier Sentenced to 70 Months for Hacking AT&T and Verizon, Stealing Data of Over 100 Million Customers

A U.S. Army soldier has been sentenced to 70 months in federal prison for hacking into telecommunications companies and stealing mobile call and text...

CloudSEK Reports Surge in AI-Driven Cyber Risks Targeting Middle East Sectors

Surge in AI-Driven Cyber Risks Threatens Middle East Sectors Cyber threats in the Middle East are escalating, with state-sponsored groups, ideologically motivated actors, and cybercriminals...