{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/azure-cloud-services/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-3168"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Azure (Cloud Services)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eIn June 2026, the threat actor Storm-3168, tracked as JadePuffer, executed a coordinated, highly automated attack against a Microsoft Azure tenant. The actor gained initial access via two service principals, likely utilizing secrets exposed in a public GitHub issue history. The campaign unfolded in two distinct phases: a reconnaissance phase involving over 300 successful read operations to map virtual machines, subscriptions, and resource groups, followed by a rapid destructive phase. During the destruction, the actor systematically attempted to delete storage accounts, Key Vaults, and App Service plans. Following the deletions, the actor performed inventory requests and retrieved access keys from remaining storage accounts, indicating an intent to secure persistent access to residual data. This incident demonstrates the capability of agentic or highly automated actors to conduct rapid, complex post-compromise operations at cloud scale.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Access: Compromised service principal client ID, client secret, and tenant ID credentials likely obtained from plaintext exposure in a public GitHub repository edit history.\u003c/li\u003e\n\u003cli\u003eEnvironment Mapping: The first service principal conducted 15.5 hours of reconnaissance, performing over 300 read operations to identify subscriptions, resource groups, and VM inventory.\u003c/li\u003e\n\u003cli\u003eEscalated Discovery: The second service principal enumerated resource groups across two subscriptions in 5 seconds to expand the scope of impact.\u003c/li\u003e\n\u003cli\u003eCredential Hunting: The attacker enumerated Azure App Service configuration stores and attempted unauthorized ListKey operations against storage accounts.\u003c/li\u003e\n\u003cli\u003eDestructive Operations: The actor initiated a parallelized destruction campaign, successfully deleting over 100 storage accounts, Azure Key Vaults, Function Apps, and App Service plans.\u003c/li\u003e\n\u003cli\u003eData Exfiltration/Persistence: Following destructive actions, the attacker made inventory requests for Site Recovery storage accounts and executed 30+ successful ListKeys requests to compromise long-term access keys.\u003c/li\u003e\n\u003cli\u003eImpact: Operational disruption resulting from the deletion of core cloud infrastructure, applications, and storage assets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign resulted in significant operational disruption through the unauthorized deletion of critical Azure cloud infrastructure, including storage accounts, databases, Key Vaults, and application plans. While no ransom note was observed, the speed and scope of the deletion are consistent with extortion-based ransomware tactics, threatening the availability and integrity of the victim's cloud data and services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure Azure environments against identity-based cloud attacks:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit public-facing source code repositories for exposed service principal secrets, client IDs, and tenant IDs.\u003c/li\u003e\n\u003cli\u003eImplement a credential rotation policy for all service principals and workload identities, particularly those used in automated CI/CD pipelines.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to all service principals, ensuring they only have the minimum permissions required for their specific function.\u003c/li\u003e\n\u003cli\u003eEnable Microsoft Defender for Cloud for all critical Azure workloads to gain visibility into anomalous resource enumeration and destructive API calls.\u003c/li\u003e\n\u003cli\u003eMonitor Azure activity logs for sudden bursts of 'Delete' or 'ListKeys' operations initiated by service principals, especially when originating from unexpected source IPs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T16:19:49Z","date_published":"2026-09-28T16:19:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jadepuffer-azure-destruction/","summary":"The threat actor Storm-3168 (JadePuffer) leveraged compromised service principal credentials to conduct high-speed reconnaissance and a large-scale destructive campaign against an Azure environment.","title":"JadePuffer (Storm-3168) Conducts Destructive Azure Tenant Compromise","url":"https://feed.craftedsignal.io/briefs/2026-09-jadepuffer-azure-destruction/"}],"language":"en","title":"CraftedSignal Threat Feed - Azure (Cloud Services)","version":"https://jsonfeed.org/version/1.1"}