securityonline.info 30 Sept 2026, 06:11 UTC

Azure Ransomware Attack Wiped Cloud Tenants and Stole Storage Keys

Azure Ransomware Attack Wiped Cloud Tenants and Stole Storage Keys
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Storm-3168

MICROSOFT Security researchers link the JADEPUFFER Azure attack, tracked by Microsoft as Storm-3168, to an agentic ransomware operation that leveraged compromised Azure service principals to wipe a cloud tenant and harvest storage keys in June 2026. The operation began with an extended discovery phase: one service principal mapped the victim’s environment for around 15.5 hours, logging over 300 read operations, followed by a second principal that scanned VMs across two subscriptions in five seconds.

Both identities shared the same network fingerprint and user agent string (python-requests/2.34.2). The subsequent destructive phase involved more than 150 destructive or credential-related actions in 35 minutes, with the wipe lasting about seven minutes and, in many cases, wiping most storage accounts, a Key Vault, a Function App and an App Service plan.

Some protections held—resource locks and deletion protection stopped several storage accounts from being deleted, illustrating the value of independent safeguards when an identity holds broad admin rights. Around 30 minutes after the wipe, the attacker’s activity included more than 30 ListKeys calls that returned storage account access keys, including for Azure Site Recovery storage.

Microsoft and Sysdig tie JADEPUFFER to earlier activities by the same actor via shared infrastructure, noting automated or scripted token use (five tokens for one identity, two deletions within a 70-second window). One potential entry point involved a public GitHub issue where an employee posted a service principal’s client ID, secret and tenant ID; the secret remained visible in an edit history, though Microsoft could not confirm its exploitation.

The overall impact appears to target backup-themed storage and recovery locks with the aim of hindering recovery, aligning with ransomware/extortion tactics, though no ransom note or confirmed data exfiltration was observed.

Defences include revoking or rotating secrets, enforcing least privilege, enabling resource locks, and deploying Defender for Cloud protections; indicators to watch include bulk ListKeys activity and sudden bursts of deletes, with a suggestion that security teams may need AI-assisted tooling to keep pace with rapid intrusions.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline