{
  "id": 10565012,
  "title": "JadePuffer crims hijacked Azure identities and used them to blow up cloud resources",
  "url": "https://urgent.news/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-10565012",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T20:30:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-cloud-resources/5299591"
  },
  "original_language": "en",
  "account": "JadePuffer, the first known agentic ransomware infection, has been linked to destructive attacks on Azure cloud resources, according to Microsoft. The attacker, tracked as Storm-3168, compromised two service principals in a cloud tenant and used them to conduct extensive Azure-focused resource destruction and credential collection. Storm-3168 conducted reconnaissance for 15 hours and 30 minutes, collecting detailed information about Azure Virtual Machines, subscriptions, resource groups, and resources. About 16 hours after the initial attack, the second compromised service principal discovered Azure App Service configuration stores and attempted to find exposed credentials and Azure OpenSearch resources. Following this, the attacker attempted to delete over 100 Azure Storage accounts, a Key Vault, Function App, and App service plan, but most of these attempts failed due to unsupported API versions. The destruction lasted about 7 minutes, but the attacker made multiple unsuccessful deletion attempts against Azure Site Recovery locks and Azure Backup protection locks protecting storage accounts. Microsoft believes the destructive activity indicates that Storm-3168 was setting up a ransomware attack, but no ransom note was sent or confirmed data exfiltration.",
  "summary": "Smells like more agentic ransomware, Redmond warns",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "JadePuffer crims hijacked Azure identities and used them to blow up cloud resources",
        "url": "https://urgent.news/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up",
        "published": "2026-09-28T20:30:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}