Microsoft: JadePuffer hijacked Azure identities to destroy cloud resources
Microsoft linked the Storm-3168 attack to JadePuffer, the first known agentic ransomware. Over 18 hours the attackers compromised two service principals in one tenant, gathered Azure resource data and deleted over 100 storage accounts, a Key Vault and a Function App.
- The attack lasted about 18 hours: 15.5 hours of discovery and 7 minutes of destruction
- The compromised service principal completed over 300 successful read operations in Azure
- More than 100 Azure Storage accounts were deleted, along with a Key Vault and Function App
- Microsoft saw no ransom note or confirmed data exfiltration
Read next
Security