Storm-3168: Agentic-driven cloud attacks using compromised service principals (opens in a new tab)
Why readFirst detailed view of JADEPUFFER/Storm-3168 activity inside Azure: compromised service principals used for bulk destruction of Storage Accounts, SQL databases, Key Vaults, Function Apps, VMs, App Services and recovery protection locks.
Microsoft Security Research tracked the actor Sysdig named JADEPUFFER in July 2026, reported as the first documented agentic ransomware operation, and found extensive Azure resource-destruction activity plus cloud credential collection staged for later exfiltration. The destructive operations ran through compromised service principals and hit Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, App Services and the recovery protection locks meant to prevent exactly this. It extends the public picture of the actor beyond Sysdig's original report and gives defenders a concrete identity surface to audit: non-human identities with broad delete rights across a subscription.
Indicators1
- Addresses
45[.]131[.]66[.]106