Active Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principals

Active Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principals

Executive Summary

The emergence of Storm-3168, tracked by Microsoft as a highly sophisticated threat actor also known as JADEPUFFER, marks a pivotal escalation in the landscape of cloud-targeted cyberattacks. This campaign is distinguished by its agentic, AI-driven orchestration and its exploitation of compromised Azure service principals to execute destructive operations at scale. The attackers leveraged automation to enumerate, destroy, and exfiltrate resources within Azure environments, with a particular focus on impairing recovery mechanisms and collecting credentials for potential future exploitation. The incident underscores the criticality of robust credential hygiene, least-privilege access, and advanced monitoring in defending against modern, automated cloud threats.

Threat Actor Profile

Storm-3168 (also referred to as JADEPUFFER) is a threat actor group identified by Microsoft for its pioneering use of agentic, AI-orchestrated attack methodologies within cloud environments. The group’s operations are characterized by rapid, parallelized actions that leverage automation to maximize impact and evade traditional detection mechanisms. Storm-3168 targets organizations utilizing Azure cloud infrastructure, exploiting weaknesses in identity and access management, particularly through the compromise of service principal credentials. The group’s tactics align with ransomware and destructive attack patterns, although no ransom demand was observed in the documented incident. Their approach demonstrates a high degree of technical sophistication, operational security, and adaptability, making them a formidable adversary in the cloud threat landscape.

Technical Analysis of Malware/TTPs

The attack initiated with the compromise of Azure service principal credentials, specifically the client ID, client secret, and tenant ID, which were inadvertently exposed in a public GitHub issue. Despite subsequent redaction, the secrets remained accessible via the edit history, illustrating the persistent risk of credential leakage in public repositories.

Once in possession of valid credentials, Storm-3168 orchestrated a multi-phase attack using at least two compromised service principals. The attackers conducted extensive reconnaissance over a 15-hour period, enumerating Azure resources such as virtual machines, subscriptions, resource groups, storage accounts, and web applications. The reconnaissance activity was characterized by a consistent network fingerprint and the use of the python-requests/2.34.2 user agent, indicating the use of custom automation scripts.

The destructive phase was executed with remarkable speed and coordination. Over a 35-minute window, the attackers performed more than 150 destructive or credential collection operations. These included over 100 attempts to delete Azure Storage Accounts (with most deletions succeeding except where resource locks were in place), deletion of Azure Key Vaults, Function Apps, and App Service Plans, and parallel attempts to delete Azure SQL Databases (which failed due to unsupported API versions). The attackers also targeted backup and recovery infrastructure by attempting to delete Azure Site Recovery and Backup protection locks, aiming to inhibit system recovery and maximize operational disruption.

Credential collection was another key objective, with over 30 successful ListKeys requests for Azure Storage Accounts, including those associated with recovery operations. The attackers utilized five unique tokens, each assigned to specific tasks such as deletion or inventory/key retrieval, demonstrating a high degree of automation and task specialization.

Role assignments played a critical role in enabling the attack. The compromised service principals had been granted the Storage Account Contributor role via group membership, allowing for destructive operations on storage resources. Direct Contributor access facilitated application-resource deletions and key retrieval, while SQL DB Contributor access enabled attempts to delete SQL databases.

The tactics, techniques, and procedures (TTPs) employed by Storm-3168 align with several MITRE ATT&CK techniques, including T1190 (Exploit Public-Facing Application), T1078.004 (Valid Accounts: Cloud Accounts), T1526 (Cloud Service Discovery), T1485 (Data Destruction), and T1490 (Inhibit System Recovery).

Exploitation in the Wild

The Storm-3168 campaign represents the first documented instance of agentic ransomware operations in the cloud. The attackers exploited publicly exposed credentials to gain initial access, then leveraged automation to conduct bulk destructive operations across Azure environments. The use of compromised service principals enabled both reconnaissance and destruction, with a clear focus on impairing recovery by targeting backup and recovery resources.

The attack was notable for its speed, scale, and precision, made possible by AI-driven orchestration. The attackers’ ability to coordinate multiple tokens and service principals in parallel allowed them to maximize impact within a short timeframe. The campaign also demonstrated the persistent risk posed by credential exposure in public repositories, as even redacted secrets can remain accessible through edit histories.

Detection of the attack was facilitated by Microsoft Defender XDR, which identified indicators such as possible data exfiltration, unusual data extraction volumes, communication with suspicious domains, access from suspicious IP addresses, and anomalous operation patterns in key resources like Key Vaults.

Victimology and Targeting

The primary targets of Storm-3168 are organizations utilizing Azure cloud infrastructure. The attack is not limited to any specific industry sector or geographic region; rather, it is relevant to any entity that employs Azure services and may be susceptible to credential exposure. The affected products include Azure Storage Accounts, Azure SQL Databases, Azure Key Vaults, Function Apps, App Service Plans, Virtual Machines, App Services, Site Recovery, Backup, Resource Groups, and Subscriptions. The attack methodology is broadly applicable to any Azure tenant where service principal credentials are exposed or insufficiently protected.

Mitigation and Countermeasures

To defend against threats like Storm-3168, organizations should prioritize the following countermeasures:

Credential hygiene is paramount. Immediately revoke or rotate any credentials that have been exposed in public repositories or issue trackers. Do not assume that redacting or deleting exposed secrets is sufficient; treat all such credentials as compromised and replace them without delay.

Role restriction is essential. Apply the principle of least privilege to all service principals and workload identities. Regularly review Azure RBAC permissions to ensure that no unnecessary privileges are granted, and remove any excessive access rights.

Resource protection should be enforced by implementing Azure resource locks and enabling storage account-level deletion protection. Restrict access to backup and recovery resources to prevent attackers from impairing system recovery capabilities.

Continuous monitoring is critical. Enable Microsoft Defender for Cloud plans for all critical workloads and monitor for unusual patterns of deletion, enumeration, or credential access. Leverage advanced detection capabilities to identify and respond to anomalous activity in real time.

AI-driven defense mechanisms, such as Project Perception and MDASH, should be employed to enhance large-scale investigation and automated response capabilities. These tools can help organizations keep pace with the speed and scale of agentic attacks.

Finally, foster a culture of security awareness and incident readiness. Regularly train staff on the risks of credential exposure and the importance of secure development practices, particularly when using public code repositories.

References

Microsoft Security Blog: Storm-3168, Sysdig: JADEPUFFER - Agentic ransomware for automated database extortion, DarkReading: JadePuffer AI Actor Compromises Azure in Destructive Cloud Attack, SOCRadar Threat Intelligence Report, WorkOS Blog: Storm-3168 explained, LinkedIn: Storm-3168 agentic-driven cloud attacks, Reddit: Storm-3168 discussions

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their digital supply chain. Our advanced analytics and continuous monitoring capabilities empower security teams to proactively identify vulnerabilities, ensure compliance, and strengthen their overall security posture. For more information about how Rescana can help your organization manage cyber risk, we are happy to answer questions at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.