Storm-3168 Uses Compromised Service Principals to Launch Agentic Attacks on Azure Cloud
Brief
Microsoft has uncovered an Azure-focused destructive campaign tied to Storm-3168, also known as JADEPUFFER, in which compromised service principals automated reconnaissance, deleted cloud resources, disrupted recovery, and collected credentials.
The activity is notable for its speed, coordinated use of multiple workload identities, and ransomware-aligned targeting of cloud data and recovery infrastructure.
Microsoft’s investigation found two compromised service principals within the same Azure tenant. One identity spent roughly 15 hours and 30 minutes performing more than 300 successful read operations, enumerating virtual machines, subscriptions, resource groups, and other resources.
