Full Report
Smells like more agentic ransomware, Redmond warns
Analysis Summary
# Incident Report: Destructive Cloud Operations by Storm-3168 (JadePuffer)
## Executive Summary
The threat actor Storm-3168 (associated with the "JadePuffer" agentic ransomware) compromised two Azure service principals to conduct reconnaissance and large-scale resource destruction. Over an 18-hour window, the attacker deleted over 100 storage accounts and key vaults while attempting to disable backup and recovery mechanisms. Although no ransom note was delivered, the behavior aligns with pre-ransomware extortion tactics driven by automated or agentic scripts.
## Incident Details
- **Discovery Date:** September 25, 2026 (Public reporting date)
- **Incident Date:** Early June 2026
- **Affected Organization:** Not disclosed (Single cloud tenant)
- **Sector:** Not disclosed
- **Geography:** Global/Cloud-based
## Timeline of Events
### Initial Access
- **Date/Time:** Early June, hour 0 of the 18-hour window.
- **Vector:** Likely credential leakage via public repository.
- **Details:** Plaintext client IDs, client secrets, and tenant IDs were previously exposed by an employee in a public GitHub issue.
### Lateral Movement
- **Reconnaissance (Hours 0–15.5):** The first compromised service principal performed over 300 read operations, mapping VMs, subscriptions, and resource groups to gain visibility across the environment.
### Data Exfiltration/Impact
- **Credential Harvesting:** The attacker targeted Azure App Service configuration stores and performed `ListKey` operations to obtain access keys for 30+ storage accounts.
- **Resource Destruction:** In a 7-minute burst, the attacker attempted to delete 100+ Azure Storage accounts, an Azure Key Vault, a Function App, and an App Service plan.
### Detection & Response
- **Discovery:** Microsoft researchers (Storm-03168 tracking) and Sysdig threat hunters identified the activity via anomalous API patterns.
- **Response Actions:** Azure resource locks and storage account-level protections successfully blocked several deletion attempts. Microsoft monitored the 18-hour progression to identify the "agentic" nature of the attack.
## Attack Methodology
- **Initial Access:** Compromised Service Principals (likely via GitHub leak).
- **Persistence:** Use of legitimate machine identities (Service Principals).
- **Privilege Escalation:** Not explicitly required; the hijacked identities already held high-level permissions.
- **Defense Evasion:** Use of legitimate Azure Resource Manager (ARM) API calls; however, the high volume of requests triggered detection.
- **Credential Access:** `ListKey` operations against storage accounts; searching App Service configs for secrets.
- **Discovery:** Massive enumeration of Azure Virtual Machines, subscriptions, and resource groups.
- **Lateral Movement:** Cloud-to-cloud movement using stolen credentials from one service principal to another within the same tenant.
- **Collection:** Automated scanning for OpenSearch and Storage Account keys.
- **Exfiltration:** Attempted (but not confirmed) via gathered storage keys.
- **Impact:** Resource Hijacking/Destruction (deleting backups and production storage).
## Impact Assessment
- **Financial:** High potential cost due to resource recreation and downtime, though specific figures were not disclosed.
- **Data Breach:** Confirmed theft of cloud access keys; data exfiltration suspected but not confirmed.
- **Operational:** Significant; loss of 100+ storage accounts, Key Vaults, and Function Apps.
- **Reputational:** Moderate; highlights risks of credential hygiene in public DevOps environments.
## Indicators of Compromise
- **User Agent:** `python-requests/2.34.2`
- **Behavioral:** Rapid, automated `Delete` operations on storage accounts; parallel attempts to delete SQL databases using unsupported API versions.
- **Infrastructure:** IP addresses linked to Storm-3168 (JadePuffer) infrastructure.
## Response Actions
- **Containment:** Leveraging Azure resource locks to prevent further deletion.
- **Eradication:** Rotation of compromised service principal secrets.
- **Recovery:** Restoration of resources (where backups were not successfully deleted).
## Lessons Learned
- **Credential Hygiene:** Plaintext secrets in GitHub remain a primary entry point for cloud catastrophic events.
- **Agentic Speed:** Attackers are now using LLM-driven or highly automated "agentic" scripts that can move from discovery to total destruction in under 24 hours.
- **API Errors:** The attacker failed to delete SQL databases due to using an "unsupported API version," suggesting the automated tools may have versioning gaps.
## Recommendations
- **Implement Resource Locks:** Apply `ReadOnly` or `CanNotDelete` locks to mission-critical Azure resources.
- **Secret Scanning:** Use automated tools (e.g., GitHub Secret Scanning) to prevent plaintext credentials from being published.
- **Least Privilege:** Audit Service Principal permissions; ensure they do not have `Delete` rights unless strictly necessary for their function.
- **Monitoring:** Set alerts for anomalous `ListKey` and `Delete` operations, especially when originating from non-standard User Agents.