Full Report
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations
Analysis Summary
# Incident Report: JADEPUFFER Destructive Azure Operations (Storm-3168)
## Executive Summary
In early June 2026, the threat actor JADEPUFFER (tracked as Storm-3168) executed a destructive cloud attack against a Microsoft Azure environment using compromised service principals. The 18-hour operation resulted in the successful deletion of numerous Azure Storage Accounts and targeted SQL databases, Key Vaults, and Virtual Machines. The incident was facilitated by credentials leaked via a public GitHub issue edit history.
## Incident Details
- **Discovery Date:** September 2026 (Publicly reported)
- **Incident Date:** Early June 2026
- **Affected Organization:** Not disclosed
- **Sector:** Technology / AI-related (implied by the use of Langflow and AI models)
- **Geography:** Global / Cloud-based
## Timeline of Events
### Initial Access
- **Date/Time:** Early June 2026
- **Vector:** Leaked Credentials via GitHub
- **Details:** Client ID, client secret, and tenant ID for a service principal were exposed in plaintext in a public GitHub issue by an organization employee. Although the secret was deleted, it remained accessible through the public edit history.
### Lateral Movement
- **Reconnaissance Phase:** The first compromised service principal conducted 16 hours of enumeration, performing over 300 read operations across Azure Virtual Machines, subscriptions, and resource groups.
- **Secondary Access:** A second service principal joined 90 minutes later, enumerating App Service configuration stores to harvest further credentials.
### Data Exfiltration/Impact
- **Destructive Phase:** In a 35-minute burst, the actor performed 150 operations, including a 7-minute window of intensive resource deletion.
- **Impact:** Successful deletion of most targeted Azure Storage accounts. Attempted deletion of SQL databases, Key Vaults, Function Apps, and App Service plans.
### Detection & Response
- **How it was discovered:** Microsoft Security Research observed anomalous service principal behavior and resource deletion spikes.
- **Response actions taken:** Azure resource locks and storage account-level deletion protections successfully blocked a portion of the deletion attempts.
## Attack Methodology
- **Initial Access:** Credential leakage (GitHub exposure).
- **Persistence:** Use of legitimate service principals.
- **Privilege Escalation:** Broad administrative permissions assigned to the compromised service principals.
- **Defense Evasion:** Use of legitimate Azure APIs and native tools; agentic AI was reportedly used to "reason" through targets to look like human or automated admin activity.
- **Credential Access:** Harvesting secrets from App Service configuration stores and public code repositories.
- **Discovery:** 16-hour reconnaissance targeting Azure subscriptions, VMs, and resource groups.
- **Lateral Movement:** Pivot from initial service principal to a second service principal within the same tenant.
- **Collection:** Enumeration of configuration stores.
- **Exfiltration:** Not explicitly detailed in this specific destructive event, though previous JADEPUFFER activity involved Bitcoin ransom demands.
- **Impact:** Resource deletion (Storage, Databases, Apps) and service disruption.
## Impact Assessment
- **Financial:** Significant costs associated with data loss and recovery efforts.
- **Data Breach:** Loss of data within deleted Storage Accounts; potential exposure of credentials.
- **Operational:** Severe disruption; multiple Azure resources (VMs, DBs, Apps) were targeted or destroyed.
- **Reputational:** High risk due to the nature of the leak (employee error on GitHub).
## Indicators of Compromise
- **Behavioral indicators:**
- Rapid spikes in `Delete` operations (e.g., 100+ storage account deletion attempts in minutes).
- Unusually high volumes of `Read` operations for resource discovery from a single service principal.
- Failed deletion attempts on SQL databases due to "unsupported API version" errors.
- Probing activity from Storm-3168 infrastructure.
## Response Actions
- **Containment measures:** Automatic triggers based on Azure Resource Locks.
- **Eradication steps:** Revocation of compromised service principal credentials; purging of GitHub history.
- **Recovery actions:** Restoration of deleted Storage Accounts (where backups/redundancy allowed).
## Lessons Learned
- **Credential Hygiene:** Removing a secret from a current file version is insufficient; public version histories (GitHub, etc.) must be scrubbed or secrets rotated immediately.
- **Defense-in-Depth:** Broad administrative permissions on service principals are dangerous. Resource locks proved to be the only successful defense once the identity was compromised.
- **AI-Driven Threats:** JADEPUFFER leverages "agentic" AI to automate complex attack chains, requiring faster, automated response mechanisms.
## Recommendations
- **Implement Least Privilege:** Restrict service principal permissions to the minimum required for their specific function.
- **Enable Resource Locks:** Apply `CanNotDelete` locks to all production-critical Azure resources.
- **Secret Scanning:** Use automated tools (e.g., GitHub Advanced Security) to block commits containing secrets before they are published.
- **Monitor Identity Logs:** Set alerts for anomalous enumeration patterns or sudden spikes in resource deletion activity by service principals.