securityaffairs.com 28 Sept 2026, 10:46 UTC

Microsoft Details Scripted Azure Attack That Deleted 100 Storage Accounts

Microsoft Details Scripted Azure Attack That Deleted 100 Storage Accounts
CyberSIXT Evidence Panel
Threat Actor
Storm-3168

MICROSOFT has detailed activity by Storm-3168, the actor it links to the JADEPUFFER ransomware operation, after two service principals in one Azure tenant were compromised. One identity spent about 15 hours and 30 minutes conducting reconnaissance, while the other began similar discovery across two subscriptions in five seconds. Both used Storm-3168 infrastructure, the same network fingerprint and the user agent `python-requests/2.34.2`. Microsoft said the timing, division of tasks and overlapping token activity strongly indicated scripted execution.

The second identity attempted more than 150 destructive or credential-related operations within 35 minutes, with the destructive activity lasting about seven minutes. It successfully deleted most of more than 100 storage accounts, as well as a Key Vault, Function App and App Service plan. Resource locks and deletion protection prevented some removals, while attempts against Azure SQL databases failed because the script used an unsupported API version.

The actor also tried to interfere with Azure Site Recovery and Azure Backup protections, then made more than 30 successful `ListKeys` requests, including against accounts associated with recovery services.

Microsoft could not confirm how the identity was compromised, but found its client ID, client secret and tenant ID had been posted in plaintext in a public GitHub issue. Although the issue was edited, the secret remained available through its edit history; Microsoft said it could not confirm whether it was used in this incident. The activity was consistent with ransomware and extortion, but no ransom note or data exfiltration was confirmed.

Microsoft advises revoking or rotating exposed credentials, reviewing their use, reducing service-principal permissions and monitoring protections around backup and recovery resources.

View full article

Article by CyberSIXT