Skip to content
Threat Feed
high threat

JadePuffer (Storm-3168) Conducts Destructive Azure Tenant Compromise

The threat actor Storm-3168 (JadePuffer) leveraged compromised service principal credentials to conduct high-speed reconnaissance and a large-scale destructive campaign against an Azure environment.

In June 2026, the threat actor Storm-3168, tracked as JadePuffer, executed a coordinated, highly automated attack against a Microsoft Azure tenant. The actor gained initial access via two service principals, likely utilizing secrets exposed in a public GitHub issue history. The campaign unfolded in two distinct phases: a reconnaissance phase involving over 300 successful read operations to map virtual machines, subscriptions, and resource groups, followed by a rapid destructive phase. During the destruction, the actor systematically attempted to delete storage accounts, Key Vaults, and App Service plans. Following the deletions, the actor performed inventory requests and retrieved access keys from remaining storage accounts, indicating an intent to secure persistent access to residual data. This incident demonstrates the capability of agentic or highly automated actors to conduct rapid, complex post-compromise operations at cloud scale.

Attack Chain

  1. Initial Access: Compromised service principal client ID, client secret, and tenant ID credentials likely obtained from plaintext exposure in a public GitHub repository edit history.
  2. Environment Mapping: The first service principal conducted 15.5 hours of reconnaissance, performing over 300 read operations to identify subscriptions, resource groups, and VM inventory.
  3. Escalated Discovery: The second service principal enumerated resource groups across two subscriptions in 5 seconds to expand the scope of impact.
  4. Credential Hunting: The attacker enumerated Azure App Service configuration stores and attempted unauthorized ListKey operations against storage accounts.
  5. Destructive Operations: The actor initiated a parallelized destruction campaign, successfully deleting over 100 storage accounts, Azure Key Vaults, Function Apps, and App Service plans.
  6. Data Exfiltration/Persistence: Following destructive actions, the attacker made inventory requests for Site Recovery storage accounts and executed 30+ successful ListKeys requests to compromise long-term access keys.
  7. Impact: Operational disruption resulting from the deletion of core cloud infrastructure, applications, and storage assets.

Impact

The campaign resulted in significant operational disruption through the unauthorized deletion of critical Azure cloud infrastructure, including storage accounts, databases, Key Vaults, and application plans. While no ransom note was observed, the speed and scope of the deletion are consistent with extortion-based ransomware tactics, threatening the availability and integrity of the victim's cloud data and services.

Recommendation

Prioritize the following actions to secure Azure environments against identity-based cloud attacks:

  • Immediately audit public-facing source code repositories for exposed service principal secrets, client IDs, and tenant IDs.
  • Implement a credential rotation policy for all service principals and workload identities, particularly those used in automated CI/CD pipelines.
  • Apply the principle of least privilege to all service principals, ensuring they only have the minimum permissions required for their specific function.
  • Enable Microsoft Defender for Cloud for all critical Azure workloads to gain visibility into anomalous resource enumeration and destructive API calls.
  • Monitor Azure activity logs for sudden bursts of 'Delete' or 'ListKeys' operations initiated by service principals, especially when originating from unexpected source IPs.

Immediate actions

Scan GitHub and internal code repositories for exposed Azure service principal secrets

Cloud Security Team 24h

Threat Hunt

Service principals executing unusual enumeration and mass deletion commands in short succession

T1485 high high confidence hunt now

Data: Azure Activity Logs

Mitigations

Rotate all service principal secrets and enforce least-privilege RBAC roles

immediate Cloud Security Team

Azure Workload Identities