A Highly Automated Destruction Campaign Wipes Out Azure Resources in Minutes
In a shocking display of cloud-based destruction, an agentic AI attacker, tracked as Storm-3168 by Microsoft, compromised Azure credentials and spent hours mapping the victim’s environment before launching a devastating attack that attempted to wipe out storage, applications, and databases. The attack, attributed to JadePuffer, was carried out with precision and speed, raising concerns about the potential for such operations in the cloud.
The attackers began by compromising two legitimate service principals within the same Azure tenant. One principal performed reconnaissance and resource discovery, conducting over 300 successful read operations in just under 16 hours. The second principal handled destructive operations, including enumerating virtual machines, subscriptions, and resource groups across multiple subscriptions. In a matter of seconds, the attacker had mapped the entire environment.
The attackers’ next move was to delete cloud-based resources at an alarming rate. They successfully deleted storage accounts, Azure Key Vault, Function App, and App Service plan in under 100 attempts. The sheer speed and scale of the destruction suggest that JadePuffer’s tactics are designed to support ransomware and extortion operations. Microsoft researchers were unable to confirm whether a ransom note was left behind or if data was exfiltrated.
The attack raises questions about how the attackers initially gained access to the compromised service principal. Microsoft found that the client ID, client secret, and tenant ID had been exposed in plaintext in a public GitHub issue by an employee of the affected organization. While it’s unclear whether this exposure was used in the attack, it serves as a stark reminder of the importance of proper account management and the potential risks associated with exposing sensitive information.
The JadePuffer operation is not without precedent. Sysdig researchers identified the group as the first documented large language model-driven ransomware operation back in July. This latest incident highlights the evolving nature of cloud-based threats and the need for organizations to stay vigilant against such attacks.
For security professionals, this incident serves as a reminder that even the most seemingly secure environments can be vulnerable to attack. The use of exposed credentials and highly automated destructive tactics should raise red flags about potential weaknesses in cloud infrastructure. As Ross Filipek, chief information security officer at Corsica Technologies, notes, “Once attackers hold an application identity, their activity can look like ordinary cloud administration.” This incident underscores the importance of regular account review, secure credential management, and continuous monitoring to prevent such attacks.
In light of this incident, organizations should take a closer look at their Azure environments and ensure that all service principals are properly secured. Regularly reviewing access keys and ensuring that sensitive information is not exposed in plaintext can go a long way in preventing similar attacks. As the threat landscape continues to evolve, staying proactive and informed will be crucial for protecting against such destructive campaigns.
Source: Dark Reading — 2026-09-28