ai-cybersecurityvendorNewsThe Broadside1 min read

JADEPUFFER used compromised service principals to destroy Azure resources

The first documented agentic ransomware operation shows what happens when workload identities become the attack path, and most orgs still treat them as plumbing, not a threat surface.


TL;DR

Microsoft detailed Storm-3168's Azure operations, two compromised service principals from the same tenant ran reconnaissance for 15+ hours, then executed a seven-minute destructive sequence of 100+ storage account deletion attempts, most succeeding. The same principals also enumerated App Service configuration stores and attempted credential collection, consistent with prior JADEPUFFER patterns Sysdig documented in July. The activity used python-requests/2.34.2 and infrastructure already linked to the actor. Microsoft calls it an evolution: agentic orchestration compressing post-compromise operations that would normally require manual coordination.

The sequence is worth walking through because the timing tells you something about how agentic ransomware changes the game.

One compromised service principal spent roughly 15 and a half hours enumerating Azure VMs, subscriptions, resource groups, and resources, 300-plus successful read operations. About 90 minutes into that run, a second compromised principal from the same tenant enumerated VMs and resource groups across two subscriptions in five seconds flat. Both used Storm-3168-linked infrastructure, the same network fingerprint, and the python-requests/2.34.2 user agent.

Sixteen hours later, the second principal enumerated Azure App Service configuration stores (the kind of place credentials get left exposed) and then, 70 seconds after the final inventory operation, launched a seven-minute destructive sequence: 100-plus storage account deletion attempts. Most succeeded. The ones that didn't were saved by Azure resource locks or storage-account-level deletion protection.

That's the diagnostic fact here: a human operator coordinating 150-plus destructive operations across multiple resource types would take far longer and probably make more mistakes. Storm-3168 didn't. Microsoft's post frames this as a broader shift toward AI-orchestrated attacks, and the timeline backs that reading.

What the practitioner does Monday

The attack didn't depend on a zero-day. It depended on compromised service principals that had enough privilege to enumerate subscriptions and delete storage accounts. The mitigation guidance Microsoft published is the same stuff most teams know they should be doing and haven't finished: enforce least privilege on workload identities, rotate secrets, protect recovery resources with deletion locks, and enable Defender for Cloud protections that flag exactly this pattern. The novel part isn't the defense, it's that the offense now executes at machine speed, and defenders who are still manually triaging identity alerts will miss the window.


Published ·Deep Fathom