JADEPUFFER carries out destructive attack on Azure environment

 

JADEPUFFER carries out destructive attack on Azure environment

The threat actor known as JADEPUFFER carried out a destructive attack against a Microsoft Azure environment in June 2026, using compromised service principals to access and delete cloud resources.

Microsoft researchers, who track the activity as Storm-3168, said the attack lasted about 18 hours. Two compromised service principals were used in the attack, one of which was mainly leveraged to explore the Azure environment. The other one carried out destructive actions and searched for credentials.

The attackers performed more than 300 discovery operations before beginning the destructive activity. They later made more than 100 attempts to delete Azure Storage accounts and most of the storage accounts were deleted.

The intruders also targeted Azure Key Vaults, Function Apps, App Services and SQL databases. Attempts to delete the database failed because the attackers used an unsupported API version.

Microsoft said resource locks and storage account deletion protections stopped some of the attacks. The company said the safeguards helped protect resources even though the attackers had broad permissions.

The compromised service principal credentials may have been exposed in a public GitHub issue, the report notes. Microsoft said the client ID, client secret and tenant ID had been posted in plaintext, and the secret remained available through the issue's edit history even after it was removed.

JADEPUFFER was previously linked to ransomware attacks against AI infrastructure. Earlier research by Sysdig found the group using an AI model to help with tasks such as credential theft, lateral movement and database destruction.

Microsoft said the latest attack appears to have been ransomware-related because the attackers also targeted recovery resources. However, researchers found no ransom note and no evidence that data was stolen.


Back to the list