Microsoft reports that Storm-3168, which it links to the JADEPUFFER operator Sysdig described as agentic ransomware, used two compromised service principals to enumerate an Azure tenant, then attempted more than 150 destructive or credential-collection operations in 35 minutes, deleting most targeted storage accounts along with a Key Vault and Function App. Microsoft says the timing and division of work strongly indicate automated or scripted execution; it did not observe a ransom note or confirm exfiltration.
It shows an automated, identity-driven cloud attack by an operator linked to agentic ransomware as seen in the defender's logs, and how independent safeguards such as resource locks limited the damage.
Key facts
As stated in the sources, with where to find them.
- The destructive sequence lasted about seven minutes and included more than 100 storage-account deletion attempts; resource locks and deletion protection saved some accounts.A seven-minute destructive sequence
- Attempts to delete SQL databases failed because the requests used an unsupported API version.A seven-minute destructive sequence
- The service principal’s secret had earlier been exposed in a public GitHub issue and remained in its edit history; Microsoft could not confirm it was the access path.Possible initial access
- Microsoft's headline calls the attacks agentic-driven, but its analysis says only that the timing strongly indicates automated or scripted execution.Introduction
Findings that cite this record
No tracked finding cites this record yet.