www.microsoft.com 25 Sept 2026, 15:35 UTC

Microsoft Links Azure Destruction Spree to Ransomware Actor Storm-3168

Microsoft Links Azure Destruction Spree to Ransomware Actor Storm-3168
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

MICROSOFT says it has identified Azure activity linked to JADEPUFFER, a threat actor tracked by the company as Storm-3168. In early June 2026, two compromised service principals in the same tenant were used for reconnaissance, resource destruction and credential collection. One spent about 15 hours and 30 minutes enumerating virtual machines, subscriptions and resources, completing more than 300 successful read operations. The second rapidly searched two subscriptions before examining App Service configuration stores, potentially looking for exposed credentials.

Microsoft observed more than 150 destructive or credential-related operations over 35 minutes, including a seven-minute sequence involving more than 100 Azure Storage deletion attempts. Most succeeded, while resource locks and account-level deletion protection blocked some. An Azure Key Vault, Function App and App Service plan were also deleted.

Attempts to remove Azure SQL databases failed because the actor used an unsupported API version, and attempts to delete Azure Site Recovery and Azure Backup protection locks were unsuccessful. Around 30 minutes later, the service principal made more than 30 successful ListKeys requests to obtain storage account access keys. Microsoft did not observe a ransom note or confirm data exfiltration, but said the destruction, recovery-targeting and key collection were consistent with ransomware and extortion tactics.

Microsoft said the identities operated with their existing Azure permissions. A client ID, secret and tenant ID belonging to one service principal had previously appeared in a public GitHub issue, although the company could not confirm that exposure caused the incident. It recommends immediately revoking or rotating exposed credentials, applying least privilege to workload identities, protecting backup resources and enabling relevant Microsoft Defender for Cloud protections.

View full article

Article by CyberSIXT