Chronicle/Attacks & incidents

Microsoft details Storm-3168's automated destruction of Azure resources through compromised service principals

AttackIncidentSignificance assistant-drafted

Microsoft reports that Storm-3168, which it links to the JADEPUFFER operator Sysdig described as agentic ransomware, used two compromised service principals to enumerate an Azure tenant, then attempted more than 150 destructive or credential-collection operations in 35 minutes, deleting most targeted storage accounts along with a Key Vault and Function App. Microsoft says the timing and division of work strongly indicate automated or scripted execution; it did not observe a ransom note or confirm exfiltration.

Why it matters

It shows an automated, identity-driven cloud attack by an operator linked to agentic ransomware as seen in the defender's logs, and how independent safeguards such as resource locks limited the damage.

Key facts

As stated in the sources, with where to find them.

  • The destructive sequence lasted about seven minutes and included more than 100 storage-account deletion attempts; resource locks and deletion protection saved some accounts.A seven-minute destructive sequence
  • Attempts to delete SQL databases failed because the requests used an unsupported API version.A seven-minute destructive sequence
  • The service principal’s secret had earlier been exposed in a public GitHub issue and remained in its edit history; Microsoft could not confirm it was the access path.Possible initial access
  • Microsoft's headline calls the attacks agentic-driven, but its analysis says only that the timing strongly indicates automated or scripted execution.Introduction

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records