Storm-3168 group uses JadePuffer malware to wipe Azure storage accounts
Microsoft Security Research documented two June attacks by a threat actor it tracks as Storm-3168, using compromised service principals to map Azure resources, steal storage account keys, and delete over 100 storage accounts along with Key Vaults, Function Apps, Virtual Machines and App Services within a seven-minute destructive phase. Some accounts survived due to Azure resource locks and storage-level protections, and attempts to delete Azure SQL databases failed. The attacker also removed Azure Site Recovery locks that normally protect backup and recovery capabilities.