JadePuffer Agentic AI Attacks Target Azure, Destroy Cloud Resources
Microsoft said one identity spent more than 15 hours mapping Azure resources before more than 150 destructive or credential-related operations followed.
- On Friday, Microsoft reported that the threat actor Storm-3168, also known as Jadepuffer, compromised two Azure service principals over an 18-hour period in early June to conduct extensive resource destruction and credential collection.
- Jadepuffer, an autonomous AI attacker first identified in July, utilized machine identities to map resources before launching a seven-minute burst of destruction, according to researchers Yossi Weizman and Tushar Mudi.
- Attackers attempted to delete more than 100 Azure Storage accounts and made more than 30 successful ListKeys requests, potentially allowing further data access, though no ransom note was ever sent.
- Microsoft found that the initial compromise likely stemmed from client IDs and secrets previously exposed in a public GitHub issue, warning that removing such disclosures does not remediate exposure until credentials are fully rotated.
- Lead security automation architect Nick Tausek of Swimlane noted that such AI-orchestrated attacks require security operations centers to connect identity activity with cloud changes before damage spreads, emphasizing coordinated response planning.
12 Articles
12 Articles
JadePuffer used compromised Azure service principals to run destructive cloud operations
Microsoft’s Storm-3168 report describes two June intrusions in which JadePuffer mapped tenant resources, retrieved storage account keys, and deleted Azure Storage accounts. The seven-minute destructive phase hit over 100 storage accounts and...
Autonomous agents attack Azure using compromised identities and destroying resources
Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft. The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration,” Microsoft …
Microsoft reconstructed an attack attributed to JadePuffer, an actor already known to have entrusted an IA with an almost complete ransomware chain. This time, a few minutes were enough to destroy a large part of an Azure environment.
Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack
Storm-3168 used compromised cloud identities to carry out a destructive attack against an Azure environment in minutes. The operation shows how a stolen application credential can give an intruder broad control over hosted data, services, and recovery protections. It also highlights the growing threat from automated cloud attacks. The activity is linked to JADEPUFFER agentic […]
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









