Urgent.News

What's breaking now, across thousands of outlets.

Tech

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Smells like more agentic ransomware, Redmond warns

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

JadePuffer, the first known agentic ransomware infection, has been linked to destructive attacks on Azure cloud resources, according to Microsoft. The attacker, tracked as Storm-3168, compromised two service principals in a cloud tenant and used them to conduct extensive Azure-focused resource destruction and credential collection.

Storm-3168 conducted reconnaissance for 15 hours and 30 minutes, collecting detailed information about Azure Virtual Machines, subscriptions, resource groups, and resources. About 16 hours after the initial attack, the second compromised service principal discovered Azure App Service configuration stores and attempted to find exposed credentials and Azure OpenSearch resources.

Following this, the attacker attempted to delete over 100 Azure Storage accounts, a Key Vault, Function App, and App service plan, but most of these attempts failed due to unsupported API versions. The destruction lasted about 7 minutes, but the attacker made multiple unsuccessful deletion attempts against Azure Site Recovery locks and Azure Backup protection locks protecting storage accounts.

Microsoft believes the destructive activity indicates that Storm-3168 was setting up a ransomware attack, but no ransom note was sent or confirmed data exfiltration.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Bootstrap for Blazor: Styling the Task Tracker

This is the final post in the series. The Task Tracker has been built, refactored, rendered, and made interactive, genuinely working since Part 4, but visually plain, using nothing but default…

More from Monday 28 September →