A highly sophisticated cyber threat has emerged, targeting Azure cloud resources with devastating consequences. The JadePuffer agentic AI attacks, first spotted in July, have been wreaking havoc on Azure tenants, leaving a trail of destruction and highlighting the need for robust cybersecurity measures.
The JadePuffer ransomware operator uses AI agents to automate its attack chain, making it nearly impossible for security teams to detect and respond to the threat. The malware conducts reconnaissance, steals credentials, and destroys core components, including cloud resources such as storage accounts, Key Vaults, Function Apps, Virtual Machines, and App Services. In one reported incident, the attacker deleted over 100 Azure Storage accounts in just seven minutes.
The attackers have been using compromised service principals – security identities that enable applications to authenticate to Azure and access assigned resources – to gain unauthorized access to cloud resources. Two service principals belonging to the same tenant were used for reconnaissance and resource discovery, as well as destructive operations and credential collection. The attacker also removed backup and recovery protections (Azure Site Recovery locks), making restoration more difficult.
This operational pattern raises concerns about ransomware extortion, although Microsoft has not reported any financial demands or data theft in the observed cases. However, the parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services.
Microsoft’s investigation revealed that attempts to delete Azure SQL databases failed due to the attacker using an unsupported API version. The attackers also attempted to remove recovery protection locks, which failed as well. Roughly half an hour after the wipe attempts, the attackers returned to perform over 30 requests for storage account keys, most of which succeeded.
The fact that the initial access occurred through compromised credentials raises concerns about the security posture of Azure tenants. Microsoft noted that credentials for one service principal appeared in a public GitHub issue before the attacks. This highlights the importance of monitoring public repositories and evaluating Azure RBAC permissions against least-privilege principles.
To mitigate these threats, system administrators should activate cloud workload protections, check for secrets in public repositories, and evaluate Azure RBAC permissions against least-privilege principles. It’s also essential to implement robust backup and recovery strategies, including regular backups of critical data and testing of recovery procedures. By taking proactive measures, organizations can reduce the risk of falling victim to these highly sophisticated cyber threats.
In light of this threat, it’s crucial for system administrators to revisit their security posture and implement additional controls to prevent unauthorized access to cloud resources. This includes regularly reviewing Azure RBAC permissions, monitoring public repositories for compromised credentials, and implementing robust backup and recovery strategies. By taking a proactive approach to cybersecurity, organizations can protect themselves against these highly sophisticated threats and minimize the risk of data loss and downtime.
Source: Bleeping Computer — 2026-09-28