← Back to feed
AI SecurityEmerging1 sourceSep 26, 2026 · 05:32via CyberPress

Storm-3168 Uses Compromised Service Principals to Launch Agentic Attacks on Azure Cloud

Brief

Microsoft has uncovered an Azure-focused destructive campaign tied to Storm-3168, also known as JADEPUFFER, in which compromised service principals automated reconnaissance, deleted cloud resources, disrupted recovery, and collected credentials.

The activity is notable for its speed, coordinated use of multiple workload identities, and ransomware-aligned targeting of cloud data and recovery infrastructure.

Microsoft’s investigation found two compromised service principals within the same Azure tenant. One identity spent roughly 15 hours and 30 minutes performing more than 300 successful read operations, enumerating virtual machines, subscriptions, resource groups, and other resources.

Read more on CyberPress→