Full Report
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
Analysis Summary
# Incident Report: JadePuffer Agentic AI Attacks on Azure Tenants
## Executive Summary
JadePuffer (tracked as Storm-3168) conducted automated, agent-driven attacks against Azure cloud environments using compromised service principals. The threat actor successfully mapped cloud resources and destroyed over 100 Azure Storage accounts, Key Vaults, and Virtual Machines within a seven-minute window. While the destructive phase was rapid, resource locks and improper API versions prevented total environment destruction, and the actor focused on credential theft to maintain future access.
## Incident Details
- **Discovery Date:** June 2026 (Reported September 2026)
- **Incident Date:** June 2026
- **Affected Organization:** Unspecified (Multiple Azure Tenants)
- **Sector:** Technology / Multi-sector
- **Geography:** Global / Cloud-based
## Timeline of Events
### Initial Access
- **Date/Time:** June 2026
- **Vector:** Credential Leak / Compromised Service Principals
- **Details:** Credentials for at least one service principal were identified as having been leaked in a public GitHub issue prior to the attack.
### Lateral Movement
- **Details:** Attackers utilized two compromised service principals within the same tenant. One was dedicated to reconnaissance, while the second was used for broad discovery, credential harvesting, and destructive operations across the Azure environment.
### Data Exfiltration/Impact
- **Details:** Destructive phase lasted approximately 7 minutes. Attackers attempted to delete Azure SQL databases (failed) and successfully deleted over 100 Storage accounts. They also targeted Key Vaults, Function Apps, and VMs.
### Detection & Response
- **Discovery:** Observed by Microsoft Security Research through anomalous service principal activity and rapid resource deletion.
- **Response Actions:** Implementation of Azure resource locks and storage-level protections prevented the deletion of some assets. Microsoft tracked the activity under the moniker Storm-3168.
## Attack Methodology
- **Initial Access:** Compromised Service Principals (leaked via GitHub).
- **Persistence:** Use of legitimate security identities (Service Principals) to maintain a presence within the cloud tenant.
- **Privilege Escalation:** Not explicitly detailed, but leveraged existing high-level permissions assigned to the compromised service principals.
- **Defense Evasion:** Attempted removal of Azure Site Recovery locks and backup protections to hinder recovery.
- **Credential Access:** Retrieval of Storage Account keys (over 30 successful requests) and Key Vault targeting.
- **Discovery:** AI-agent driven reconnaissance to map cloud resources and identify AI training datasets/vector databases.
- **Lateral Movement:** Cloud-native movement via service principal authentication across different Azure services.
- **Collection:** Focus on AI assets, training datasets, and vector databases (via EncForge tool).
- **Exfiltration:** Potential data theft (unconfirmed in this specific instance, though typical for this actor).
- **Impact:** Mass deletion of storage accounts and cloud components; attempted disruption of SQL databases.
## Impact Assessment
- **Financial:** High potential cost due to resource recreation and downtime; ransom demands typical for JadePuffer.
- **Data Breach:** Compromise of storage account keys; potential exposure of AI models and datasets.
- **Operational:** Significant disruption; destruction of core components including VMs and Function Apps.
- **Reputational:** High risk due to the loss of proprietary AI training data and customer-facing services.
## Indicators of Compromise
- **Behavioral indicators:**
- Rapid, automated API calls for resource deletion (7-minute burst).
- Multiple failed attempts to delete SQL databases using unsupported API versions.
- Unusual service principal activity originating from non-standard locations or times.
- Removal of "Azure Site Recovery" locks.
## Response Actions
- **Containment measures:** Identification and disabling of compromised service principals.
- **Eradication steps:** Revocation of all leaked secrets found in public repositories (GitHub).
- **Recovery actions:** Restoration of deleted storage accounts from backups (where Site Recovery locks held).
## Lessons Learned
- **AI-Driven Speed:** The "agentic" nature of the attack allows for near-instantaneous destruction once access is gained, leaving little time for human intervention.
- **Resource Protection Efficacy:** Azure resource locks were the primary factor in preventing total data loss.
- **Secret Management:** Leaked credentials in public repositories remain a primary entry point for high-impact cloud breaches.
## Recommendations
- **Identity Security:** Implement strict Azure RBAC permissions following the principle of least privilege for service principals.
- **Secret Scanning:** Use automated tools to scan public and private repositories (e.g., GitHub Advanced Security) for leaked secrets.
- **Resilience:** Apply "CanNotDelete" resource locks to all production-critical Azure resources.
- **Monitoring:** Enable and monitor Azure Resource Manager (ARM) logs for mass deletion events or unauthorized key access.