Storm-3168 Threat Actor Exploits Compromised Service Principals for Destructive Azure Attacks

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. This investigation found extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could facilitate future exfiltration. According to reporting by Microsoft Security Research, these findings expand the publicly documented activity associated with JADEPUFFER, tracked by Microsoft as Storm-3168, demonstrating an evolution in the threat actor’s cloud operations.

Attack Overview

Microsoft observed two compromised service principals belonging to the same tenant. One performed reconnaissance and resource discovery, while the other executed destructive operations and credential collection. In early June 2026, one of the compromised service principals enumerated Azure Virtual Machines, subscriptions, resource groups, and resources for about 15 hours and 30 minutes, conducting over 300 successful read operations. This breadth of activity provided the threat actor visibility across the organization’s Azure environment.

Destructive Sequence

Less than one second after an unsuccessful ListKey operation against a non-existent storage account, the second compromised service principal initiated destructive activities, attempting over 150 destructive or credential collection-related operations in 35 minutes. The destructive sequence lasted about 7 minutes, involving over 100 storage account deletion attempts, most of which were successful. However, Azure resource locks and storage account-level deletion protection blocked some deletion attempts, highlighting the importance of independent safeguards.

Credential Collection and Implications

About 30 minutes after the final destructive activity, the same service principal made an inventory request for Azure Storage Accounts and successfully sent over 30 ListKeys requests, asking ARM to return each storage account’s access keys. This activity indicates a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale.

Microsoft recommends several mitigations to reduce the risk and impact of similar activities, including enabling appropriate Microsoft Defender for Cloud plans, protecting application credentials, and applying least privilege to service principals. Organizations are urged to continuously assess their security posture to defend against evolving threats.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Unit 42 Experts Address Common Cybersecurity Myths and Misconceptions

In the ever-evolving landscape of cybersecurity, misconceptions can lead organizations to adopt ineffective strategies that leave them vulnerable to attacks. Insights from Unit 42...

CWME_REVIEW_REQUIRED

The 2026-2027 Dream with Us Design Challenge, organized by NASA, invites middle and high school students to participate in a project focused on the...

Data Dynamics CEO emphasizes data sovereignty as crucial for cybersecurity in the Middle East.

Piyush M, CEO of Data Dynamics, explains why data sovereignty has become critical to cybersecurity, resilience and the protection of sensitive information Data sovereignty has...

Kiteworks Advises Customers to Shut Down Systems Amid Federal Cyberattack Warning

Software company Kiteworks has issued a warning to its customers, advising them to shut down the company’s platform over the weekend due to concerns...