← Back to feed
AI SecurityEmerging1 sourceSep 25, 2026 · 15:35via Microsoft Security Blog

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Brief

In this article

  • Attack overview
  • Technical analysis
  • Mitigation and protection guidance
  • References
  • Learn More

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration.

These findings expand the publicly documented activity associated with JADEPUFFER, tracked by Microsoft as Storm-3168, demonstrating an evolution in the threat actor’s cloud operations and providing the first detailed view into its Azure activity. We identified bulk destructive operations in a compromised Azure environment.

Read more on Microsoft Security Blog→