JadePuffer agentic AI attacks target Azure, destroy cloud resources

A new breed of AI-powered attacks is wreaking havoc on Azure cloud resources, leaving a trail of destruction and raising concerns about the future of cloud security. JadePuffer, a ransomware operator that emerged in July, has been targeting Azure tenants with sophisticated agent-driven attacks that automate the entire attack chain.

The malware uses artificial intelligence (AI) agents to conduct reconnaissance, steal credentials, and destroy core components. In two observed cases, Microsoft Security Research noted that JadePuffer mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts. The destructive stage lasted a mere seven minutes, targeting over 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services.

The attackers used compromised service principals, which are security identities that enable applications to authenticate to Azure and access assigned resources. Two service principals were involved in the attacks: one was used for reconnaissance and resource discovery, while the other performed destructive operations and credential collection. The threat actor also removed backup and recovery protections (Azure Site Recovery locks), making restoration more difficult.

Microsoft tracks the JadePuffer threat actor as Storm-3168, which suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type. This is evident in attempts to delete Azure SQL databases, which failed due to the use of an unsupported API version. Similarly, attempts to remove recovery protection locks also failed.

The attackers’ goal appears to be not only financial gain through ransomware extortion but also to make restoration more difficult. Roughly half an hour after the wipe attempts, Storm-3168 returned to perform over 30 requests for storage account keys, most of which succeeded. The researchers note that the initial access could not be determined, but credentials for one service principal appeared in a public GitHub issue before the attacks.

This new wave of AI-powered attacks highlights the need for organizations to take proactive measures to prevent such incidents. Microsoft recommends several mitigation steps, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.

For system administrators, it’s essential to build a robust security blueprint that can withstand AI-speed attacks. This includes monitoring cloud resources, regularly updating software and plugins, and implementing least-privilege access controls. By taking these precautions, organizations can reduce the risk of falling victim to such sophisticated attacks and ensure the integrity of their cloud infrastructure.

In light of this threat, it’s crucial for system administrators to stay vigilant and adapt to the evolving landscape of AI-powered attacks. By doing so, they can protect their organization’s sensitive data from the likes of JadePuffer and its associates.


Source: Bleeping Computer — 2026-09-28