Storm-3168 group uses JadePuffer malware to wipe Azure storage accounts
Microsoft Security Research documented two June attacks by a threat actor it tracks as Storm-3168, using compromised service principals to map Azure resources, steal storage account keys, and delete over 100 storage accounts along with Key Vaults, Function Apps, Virtual Machines and App Services within a seven-minute destructive phase. Some accounts survived due to Azure resource locks and storage-level protections, and attempts to delete Azure SQL databases failed. The attacker also removed Azure Site Recovery locks that normally protect backup and recovery capabilities.
GoKawiil's interpretation of the reporting above, not reported fact.
Removing backup protections before destroying resources suggests an attempt to prevent victims from recovering without paying, though Microsoft has not confirmed any ransom demands or data theft in these specific incidents. The use of AI agents to automate reconnaissance, credential theft and destruction, as reported by Sysdig, points toward attackers increasingly using automation to speed up and scale cloud-focused intrusions. The partial failures caused by resource locks and SQL protections indicate that existing Azure safeguards can blunt, though not fully stop, such destructive campaigns.
- Microsoft observed Storm-3168 delete over 100 Azure storage accounts in a seven-minute destructive burst.
- Attackers removed Azure Site Recovery locks, potentially undermining backup-based recovery.
- Some resources survived thanks to Azure resource locks, and SQL database deletion attempts failed.
YubiKey 5C NFC Security Key — With attackers like JadePuffer automating credential theft and lateral movement across Azure tenants, hardware-backed MFA is one of the strongest defenses against compromised service principals and stolen keys. A YubiKey adds phishing-resistant authentication to admin and cloud accounts, making it far harder for AI-driven attack chains to hijack credentials and reach destructive stages.”}[trimmed] {
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-28
Published there as: “JadePuffer agentic AI attacks target Azure, destroy cloud resources”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.