<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Azure (Cloud Services) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/azure-cloud-services/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:19:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/azure-cloud-services/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>JadePuffer (Storm-3168) Conducts Destructive Azure Tenant Compromise</title><link>https://feed.craftedsignal.io/briefs/2026-09-jadepuffer-azure-destruction/</link><pubDate>Mon, 28 Sep 2026 16:19:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-jadepuffer-azure-destruction/</guid><description>The threat actor Storm-3168 (JadePuffer) leveraged compromised service principal credentials to conduct high-speed reconnaissance and a large-scale destructive campaign against an Azure environment.</description><content:encoded><![CDATA[<p>In June 2026, the threat actor Storm-3168, tracked as JadePuffer, executed a coordinated, highly automated attack against a Microsoft Azure tenant. The actor gained initial access via two service principals, likely utilizing secrets exposed in a public GitHub issue history. The campaign unfolded in two distinct phases: a reconnaissance phase involving over 300 successful read operations to map virtual machines, subscriptions, and resource groups, followed by a rapid destructive phase. During the destruction, the actor systematically attempted to delete storage accounts, Key Vaults, and App Service plans. Following the deletions, the actor performed inventory requests and retrieved access keys from remaining storage accounts, indicating an intent to secure persistent access to residual data. This incident demonstrates the capability of agentic or highly automated actors to conduct rapid, complex post-compromise operations at cloud scale.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Access: Compromised service principal client ID, client secret, and tenant ID credentials likely obtained from plaintext exposure in a public GitHub repository edit history.</li>
<li>Environment Mapping: The first service principal conducted 15.5 hours of reconnaissance, performing over 300 read operations to identify subscriptions, resource groups, and VM inventory.</li>
<li>Escalated Discovery: The second service principal enumerated resource groups across two subscriptions in 5 seconds to expand the scope of impact.</li>
<li>Credential Hunting: The attacker enumerated Azure App Service configuration stores and attempted unauthorized ListKey operations against storage accounts.</li>
<li>Destructive Operations: The actor initiated a parallelized destruction campaign, successfully deleting over 100 storage accounts, Azure Key Vaults, Function Apps, and App Service plans.</li>
<li>Data Exfiltration/Persistence: Following destructive actions, the attacker made inventory requests for Site Recovery storage accounts and executed 30+ successful ListKeys requests to compromise long-term access keys.</li>
<li>Impact: Operational disruption resulting from the deletion of core cloud infrastructure, applications, and storage assets.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign resulted in significant operational disruption through the unauthorized deletion of critical Azure cloud infrastructure, including storage accounts, databases, Key Vaults, and application plans. While no ransom note was observed, the speed and scope of the deletion are consistent with extortion-based ransomware tactics, threatening the availability and integrity of the victim's cloud data and services.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to secure Azure environments against identity-based cloud attacks:</p>
<ul>
<li>Immediately audit public-facing source code repositories for exposed service principal secrets, client IDs, and tenant IDs.</li>
<li>Implement a credential rotation policy for all service principals and workload identities, particularly those used in automated CI/CD pipelines.</li>
<li>Apply the principle of least privilege to all service principals, ensuring they only have the minimum permissions required for their specific function.</li>
<li>Enable Microsoft Defender for Cloud for all critical Azure workloads to gain visibility into anomalous resource enumeration and destructive API calls.</li>
<li>Monitor Azure activity logs for sudden bursts of 'Delete' or 'ListKeys' operations initiated by service principals, especially when originating from unexpected source IPs.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>