{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/azure-site-recovery/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-3168"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Azure App Service","Azure Storage Account","Azure SQL Database","Azure Key Vault","Azure Function App","Azure Site Recovery","Azure Backup"],"_cs_severities":["high"],"_cs_tags":["cloud-security","identity-theft","azure","ransomware"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft researchers have identified a sophisticated cloud-focused campaign orchestrated by the threat actor Storm-3168, also known as JADEPUFFER. This activity represents an evolution in cloud-native threats, characterized by the use of agentic-driven automation to perform high-speed reconnaissance, resource destruction, and credential harvesting within Azure environments. By leveraging compromised service principals, the actor executes multi-threaded API operations to delete storage accounts, databases, and key vaults. The actor exhibits a deep understanding of cloud infrastructure, evidenced by the use of distinct service principals for specific tasks, such as reconnaissance versus destructive operations. This coordinated effort allows for rapid, large-scale impact on cloud resources, often bypassing traditional manual intervention speeds. Defenders should prioritize auditing workload identities, as the actor specifically targets service principals exposed in public repositories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained through compromised service principal credentials, often harvested from public version control systems like GitHub issue histories.\u003c/li\u003e\n\u003cli\u003eThe actor deploys automated scripts using the 'python-requests/2.34.2' user-agent to interact with the Azure Resource Manager (ARM) API.\u003c/li\u003e\n\u003cli\u003eReconnaissance is conducted using one service principal to enumerate virtual machines, resource groups, and subscriptions for over 15 hours.\u003c/li\u003e\n\u003cli\u003eA second service principal performs rapid discovery of configuration stores and storage accounts to identify high-value targets.\u003c/li\u003e\n\u003cli\u003eThe actor executes a highly coordinated, 7-minute destructive sequence, initiating over 100 parallel requests to delete Azure Storage accounts, Key Vaults, and Function Apps.\u003c/li\u003e\n\u003cli\u003eSimultaneously, the actor attempts to delete SQL databases and backup protection locks to disable recovery capabilities.\u003c/li\u003e\n\u003cli\u003eFinal credential exfiltration is performed by issuing 'ListKeys' requests against surviving storage accounts to harvest access keys.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful attacks result in the bulk deletion of business-critical cloud infrastructure, including Azure Storage Accounts, Key Vaults, and Function Apps. The harvesting of access keys provides persistent, unauthorized access to data stored within those accounts, even after the initial compromise is identified. This activity threatens business continuity and data confidentiality, particularly for organizations with improperly secured workload identities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit Azure AD and GitHub for exposed Service Principal secrets; rotate any found in public history.\u003c/li\u003e\n\u003cli\u003eImplement and enforce Azure resource locks and storage account-level deletion protections to mitigate the impact of rogue API calls.\u003c/li\u003e\n\u003cli\u003eUse Microsoft Defender for Cloud to monitor for unusual API activity associated with workload identities.\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege for all Service Principals to ensure they cannot perform destructive operations outside of their required scope.\u003c/li\u003e\n\u003cli\u003eDeploy detections for unusual User-Agent strings (e.g., 'python-requests/2.34.2') originating from non-authorized infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T17:12:10Z","date_published":"2026-09-25T17:12:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-storm-3168-azure/","summary":"Storm-3168 (linked to JADEPUFFER) leverages compromised Azure service principals to execute automated resource destruction and credential exfiltration through AI-orchestrated cloud API manipulation.","title":"Storm-3168 Cloud Attack Campaign","url":"https://feed.craftedsignal.io/briefs/2026-09-storm-3168-azure/"}],"language":"en","title":"CraftedSignal Threat Feed - Azure Site Recovery","version":"https://jsonfeed.org/version/1.1"}