MICROSOFT says an “agentic threat actor” known as JadePuffer, or Storm-3168, compromised an Azure tenant in an attack that attempted to destroy cloud resources. The incident took place in early June and involved two legitimate service principals. One spent about 15½ hours mapping virtual machines, subscriptions, resource groups and other assets, carrying out more than 300 successful read operations. The second performed further discovery, searched configuration stores for potentially exposed credentials and then launched the destructive activity.
The attacker made more than 100 attempts to delete storage accounts, most of which succeeded, as well as an Azure Key Vault, Function App and App Service plan. Attempts to delete multiple Azure SQL databases failed because an unsupported API version was used. Around 30 minutes later, the service principal listed storage accounts, including Site Recovery-related accounts, and made more than 30 successful ListKeys requests to obtain access keys.
Microsoft said the activity was consistent with ransomware or extortion tactics, but it did not observe a ransom note or confirm successful data exfiltration.
Microsoft found that the affected organisation’s client ID, client secret and tenant ID had previously been posted in plaintext in a public GitHub issue. The information remained available in the issue’s edit history after being removed, although Microsoft could not confirm that the exposed credentials enabled the compromise. Researchers also differed over whether the Azure operation proved that AI directed every step, describing the evidence as coordinated automation.
Microsoft advised enabling relevant Defender for Cloud plans, protecting and assessing application secrets, rotating exposed credentials, and applying least privilege to service principals and other workload identities.