JadePuffer Uses AI Agents to Wipe Azure Resources in Minutes


azure JadePuffer
Image credit: Microsoft

JadePuffer ransomware is targeting Azure tenants with agent-driven attacks that automate reconnaissance, credential theft, lateral movement, persistence, and destructive actions, according to Microsoft.

Microsoft tracks the threat actor behind JadePuffer as Storm-3168. The ransomware emerged in July 2026 and uses AI agents to automate much of the attack chain.

Storm-3168 deleted more than 100 Azure storage accounts

Microsoft Security Research observed two Storm-3168 attacks in June that targeted Azure environments.

The attacker mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts. Microsoft says the destructive phase lasted only seven minutes and targeted more than 100 storage accounts.

Storm-3168 also targeted Azure Key Vaults, Function Apps, Virtual Machines, App Services, and Azure SQL databases.

Most targeted storage accounts were deleted, although some survived because of resource locks and storage account-level protections.

Compromised service principals gave attackers access

Storm-3168 used two compromised service principals belonging to the same Azure tenant.

Microsoft could not determine the exact initial access method. However, credentials for one of the service principals had appeared in a public GitHub issue before the attacks.

The attacker also tried to remove backup and recovery protections, including Azure Site Recovery locks, which could make restoration more difficult.

Attempts to delete Azure SQL databases failed because the attacker used an unsupported API version.

Around 30 minutes after the destructive activity, Storm-3168 returned and made more than 30 requests for storage account keys. Most of those requests succeeded.

Microsoft warns organizations to protect Azure credentials

The removal of recovery protections could support ransomware extortion. However, Microsoft says it observed no financial demands or confirmed data theft during the attacks.

Administrators should check public repositories for exposed credentials and secrets, especially credentials linked to Azure service principals.

Organizations should also review Azure RBAC permissions, enforce least-privilege access, and enable appropriate cloud workload protections.

The campaign adds to recent attacks focused on cloud credentials. Hackers have also been mass-scanning Vite servers to steal AWS and Azure credentials.

Microsoft has also continued urging Entra ID customers to move from SMS to passkeys as it pushes organizations toward stronger authentication.

Meanwhile, researchers recently found that compromised GitHub Actions had been re-enabled while malicious Mini Shai-Hulud code remained active.

Via BleepingComputer

More about the topics: Azure, Cybersecurity, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages