Microsoft Storm-3168 / JADEPUFFER (25 Sep / THN 28 Sep): compromised Azure service principals → bulk storage/Key Vault deletions
Microsoft Security Research (Yossi Weizman, Tushar Mudi; published 25 September 2026; The Hacker News amplified 28 Sep) documents Azure-focused destructive activity by JADEPUFFER, tracked as Storm-3168 — an evolution of the actor Sysdig described in July 2026 as the first documented agentic ransomware operation (Langflow CVE-2025-3248 initial path; ENCFORGE later). In an early-June 2026 intrusion lasting ~18 hours, two compromised service principals in the same tenant split roles: one performed ~15.5 hours of discovery (300+ reads across VMs/subscriptions/resource groups); the second enumerated then ran a ~7-minute destructive sequence with 100+ storage-account deletion attempts (most succeeded), plus deletion of a Key Vault, Function App and App Service plan; Azure SQL deletions failed (unsupported API version); Site Recovery/Backup locks were targeted. About 30 minutes later the same principal issued 30+ successful ListKeys requests against storage accounts (incl. Site Recovery-related). User agent python-requests/2.34.2; five unique tokens observed. Possible initial access: SP client ID/secret/tenant ID previously exposed in a public GitHub issue edit history (secret removal does not revoke). Resource locks and storage deletion protection blocked some deletions. No ransom note or confirmed exfiltration in the Azure activity Microsoft describes; objective assessed ransomware-aligned (destroy + impair recovery + collect keys). IoCs include 45.131.66.106, 34.153.223.102, 64.20.53.230. Primary: Microsoft Security Blog; wire: THN 28 Sep.
- Product
- Microsoft Azure (service principals / Entra workload identities; Storage, Key Vault, Function Apps, App Service, SQL, Backup/Site Recovery locks)
- Versions
- n/a (identity/configuration abuse; not a product CVE). Actor historically tied to Langflow CVE-2025-3248 in Sysdig’s July 2026 JADEPUFFER write-up.
- Exploited in Australia?
- unknown
- Patch to
- Inventory and least-privilege service principals; revoke/rotate any publicly exposed client secrets (edit-history counts); prefer short-lived credentials. Enable Azure resource locks and storage deletion protection; protect Backup/Site Recovery controls. Enable Defender for Cloud plans (Resource Manager, Storage, Key Vault, App Service, Databases); hunt ListKeys bursts, mass deletes, python-requests/2.34.2 ARM traffic, and Microsoft IoCs. Separate recon vs admin workload identities; monitor App Service config stores for credential theft paths.
Primary: Microsoft Security Blog — Storm-3168 agentic cloud attacks via compromised service principals (25 Sep 2026) · Vendor: Microsoft Security Research (Storm-3168 / JADEPUFFER) · CVE: CVE-2025-3248 · The Hacker News — JADEPUFFER Azure service-principal destruction (28 Sep 2026)
