Storm-3168 exploited stolen Azure identities to destroy cloud infrastructure

← Back to the feed

Storm-3168 exploited stolen Azure identities to destroy cloud infrastructure

The Register · 4 hours ago

Microsoft has revealed that Storm-3168, the criminal group behind JadePuffer (the first documented agentic ransomware infection), conducted a separate campaign using stolen Azure service principal identities to destroy cloud resources and collect credentials. The 18-hour attack in early June targeted cloud storage, databases and other Azure infrastructure, demonstrating how the same adversary is leveraging multiple attack vectors to cause damage and facilitate future compromise.

The attackers compromised two service principals belonging to the same tenant, using one for reconnaissance and the other for destructive operations. During the attack, they performed over 300 successful read operations to map the organisation's Azure environment, then attempted to delete more than 100 Azure Storage accounts (most successfully), along with Key Vaults, Function Apps and Azure SQL databases. The group collected more than 30 storage account access keys at the end of the attack, which could be used for future exfiltration. The initial compromise may have resulted from an employee previously exposing credentials in plaintext on GitHub.

  • Storm-3168 used stolen Azure identities to destroy cloud resources over 18 hours
  • Performed 300+ reconnaissance operations before attempting 150+ destructive actions
  • Collected storage account keys for potential future attacks

Cybersecurity Technology

Read the full article at the source →

Originally published by The Register as “JadePuffer crims hijacked Azure identities and used them to blow up cloud resources”.