JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
Smells like more agentic ransomware, Redmond warns
Microsoft has detected a malicious actor, Storm-3168, responsible for stolen Azure identities and destructive attacks on cloud resources. The threat actor, linked to the JadePuffer ransomware, conducted an 18-hour attack over early June, compromising two service principals for extensive Azure-focused resource destruction and credential collection.
The compromised service principals were used for reconnaissance, resource discovery, and destructive operations, including the deletion of over 100 Azure Storage accounts and an Azure Key Vault. The attacker also attempted to delete Azure SQL databases, but failed due to unsupported API versions. Despite the extensive damage, no ransom note was sent, and no data exfiltration was confirmed.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.