JADEPUFFER Linked Attackers Used Compromised Service Principals To Delete Azure Resources

Published:

Microsoft has disclosed new details about a destructive cyberattack linked to the threat actor known as JADEPUFFER, revealing how compromised Azure service principals were used to conduct extensive reconnaissance, collect credentials, and delete cloud resources within a customer’s Microsoft Azure environment. The company tracks the activity under the name Storm-3168 and said the incident occurred over an 18 hour period in early June 2026. According to Microsoft Security researchers Yossi Weizman, Tushar Mudi, and the Microsoft Security Research team, the operation targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. Microsoft described the activity as an evolution in the group’s operational approach, highlighting how compromised cloud identities can be leveraged to carry out destructive actions against enterprise environments.

JADEPUFFER first came to wider attention following earlier research from Sysdig, which described it as the first ransomware operation reportedly executed end to end with assistance from a large language model. That campaign exploited the Langflow remote code execution vulnerability tracked as CVE-2025-3248 to gain initial access before harvesting credentials, moving deeper into targeted environments, encrypting Nacos service configuration files, deleting original database tables, and leaving a Bitcoin ransom demand. Researchers later observed the same Langflow instance being targeted again through a compiled Go based ransomware strain known as ENCFORGE. The malware was designed specifically for artificial intelligence infrastructure and scanned for nearly 180 file extensions, including AI model checkpoints, vector databases, training datasets, embedding indexes, macOS Keychain stores, Xcode project files, and Apple productivity documents. Sysdig noted that while the individual attack techniques were already familiar to security professionals, the notable aspect was the ability of an AI assisted workflow to combine multiple stages of a ransomware campaign into a coordinated operation against exposed infrastructure.

Microsoft’s latest investigation found that two compromised service principals associated with the same Azure tenant played different roles throughout the attack. One identity focused primarily on reconnaissance and resource discovery, while the second was used for destructive operations and credential collection. During nearly 16 hours of activity, attackers carried out more than 300 read operations while enumerating Azure Virtual Machines, subscriptions, resource groups, and other cloud resources. Roughly 90 minutes later, the second service principal rapidly enumerated virtual machines and resource groups across two subscriptions within seconds before expanding its discovery efforts to Azure App Service configuration stores, likely searching for exposed credentials. After completing reconnaissance, the attackers initiated more than 150 destructive or credential collection related operations within a period of approximately 35 minutes. The most aggressive phase lasted around seven minutes and included more than 100 attempts to delete Azure Storage accounts, while additional operations targeted Azure Key Vault, Function App, App Service plans, and several Azure SQL databases. Microsoft reported that attempts to remove Azure SQL databases were unsuccessful because the attackers relied on an unsupported API version, while deletion protection and Azure resource locks prevented some storage accounts from being removed despite the attackers holding broad administrative privileges.

The investigation also identified how the compromise may have occurred. Microsoft said the affected service principal’s client ID, client secret, and tenant ID had previously been exposed in plain text within a public GitHub issue created by an employee of the impacted organization. Although the sensitive information was later removed, it remained accessible through the platform’s public edit history, providing an opportunity for misuse. Microsoft also detected repeated probing activity from infrastructure associated with Storm-3168 targeting Azure App Services across multiple customers, suggesting that portions of the operation were likely automated or scripted. Based on the deletion of cloud resources, backup components, and recovery related assets, Microsoft assessed that the campaign aligned with ransomware objectives by attempting to reduce the victim’s ability to restore affected systems. However, the company said it did not observe a ransom note or evidence of successful data exfiltration during the incident. Microsoft added that the campaign reflects an increasing use of AI assisted techniques to coordinate complex post compromise activity across cloud environments, reinforcing the need for organizations to strengthen identity protection, safeguard service principal credentials, implement resource locks, and adopt AI driven defensive capabilities to improve detection and response against evolving cloud focused threats.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img