DEV Community

Cyber Updates 365
Cyber Updates 365

Posted on Originally published at cyberupdates365.com

JadePuffer (Storm-3168) Wipes Azure Cloud Resources: Service Principal Abuse & Agentic Threats

Microsoft Security Research has linked a destructive cloud-wiping campaign to JADEPUFFER (tracked by Microsoft as Storm-3168). Leveraging two compromised Azure service principals, the threat group conducted extensive reconnaissance before executing more than 150 destructive operations in roughly 35 minutes—deleting virtual machines, network subnets, disks, and attempting to wipe recovery storage accounts.

This attack represents a critical evolution for JADEPUFFER, previously identified by Sysdig as the first threat group running end-to-end autonomous AI agent ransomware operations.

đź”— Original Incident Investigation & Technical Breakdown:

Read the complete architectural teardown, timeline, and mitigation strategies on CyberUpdates365: JadePuffer Storm-3168 Azure Attack.


Attack Breakdown: From Leaked Secrets to Cloud-Scale Destruction

  1. Compromised Non-Human Workload Identities: The intrusion relied on two service principals. Notably, the credentials (tenant ID, client ID, and client secret) had previously been exposed in a public GitHub issue history—proving once again that editing out secrets does not erase them from public repository metadata.
  2. 15-Hour Methodical Reconnaissance: The first service principal executed over 300 read operations across 15.5 hours, mapping resource groups, virtual networks, subnets, and storage accounts without raising basic volume-based alerts.
  3. High-Velocity Destructive Burst: The second service principal initiated a 35-minute blitz, deleting production VMs, subnets, disks, and targeting backup/Terraform recovery storage to inhibit rollback.
  4. Credential Harvesting via ListKeys: Storm-3168 queried storage account keys after the destructive actions, collecting secrets that could enable persistent out-of-band access or future data exfiltration.

For continuous intelligence on autonomous AI attack vectors and enterprise identity defenses, visit the CyberUpdates365 AI-Era Threats & Agentic Security Hub. Cloud security teams should also inspect our breakdown of the Critical Langflow AI Framework Flaw, which JADEPUFFER previously weaponized.


Key Takeaways for Azure & Cloud SecOps Teams

  • Treat Workload Identities Like Domain Admins: Service principals and Managed Identities often operate with overly broad roles (Contributor, Storage Account Contributor). Enforce least privilege with Just-In-Time (JIT) access and Microsoft Entra Workload ID protection.
  • Rotate Exposed Secrets Immediately: Deleting or editing a secret from GitHub, GitLab, or tickets does NOT revoke it. Immediately rotate credentials and invalidate existing session tokens.
  • Enable Soft Delete & Immutable Resource Locks: Implement Azure resource locks (CanNotDelete) and immutable backup vaults across critical state storage (Terraform state, recovery snapshots, database backups) to prevent single-identity wipeout attacks.

Read the full investigation and defense recommendations at CyberUpdates365.

Top comments (0)