Tech News
← Home  ·  All topics

Jadepuffer

2 GoKawiil briefs on this topic

Microsoft says AI-driven actor JadePuffer wiped Azure cloud resources in minutes

Microsoft Security Research reported that a threat actor it tracks as Storm-3168, also known as JadePuffer, compromised two legitimate Azure service principals belonging to one tenant and used them to map the victim's environment before launching an automated destruction campaign against storage, applications, databases and backup controls. The attack, which occurred in early June, involved one account spending over 15 hours on reconnaissance while a second executed rapid, wide-ranging discovery and destructive operations within seconds. Microsoft said the pattern matches ransomware or extortion tactics but noted it did not observe a ransom note or confirm data theft.

Storm-3168 group uses JadePuffer malware to wipe Azure storage accounts

Microsoft Security Research documented two June attacks by a threat actor it tracks as Storm-3168, using compromised service principals to map Azure resources, steal storage account keys, and delete over 100 storage accounts along with Key Vaults, Function Apps, Virtual Machines and App Services within a seven-minute destructive phase. Some accounts survived due to Azure resource locks and storage-level protections, and attempts to delete Azure SQL databases failed. The attacker also removed Azure Site Recovery locks that normally protect backup and recovery capabilities.