Back
JADEPUFFER-linked attackers used compromised identities to delete Azure resources
SiTech AI Team2 წთ. საკითხავი

JADEPUFFER-linked attackers used compromised identities to delete Azure resources

Microsoft says attackers linked to JADEPUFFER used two compromised service principals to map and damage an Azure environment. The seven-minute destructive sequence included more than 100 storage account deletion attempts.

Two identities in a coordinated operation

Microsoft security researchers identified activity linked to JADEPUFFER, which the company tracks as Storm-3168. In early June 2026, the attackers used two compromised service principals in one Azure tenant. One handled reconnaissance and resource discovery, while the other performed discovery, destructive actions, and credential collection.

The first identity enumerated virtual machines, subscriptions, resource groups, and other resources for 15 hours and 30 minutes, completing more than 300 successful read operations. About 90 minutes after that activity began, the second identity enumerated virtual machines and resource groups across two subscriptions in five seconds. Both used Storm-3168-linked infrastructure, the same network fingerprint, and the python-requests/2.34.2 user agent.

A seven-minute deletion sequence

Seventy seconds after its final inventory operation, the second identity began the destructive phase. It attempted more than 150 destructive or credential-collection operations within 35 minutes. The core sequence lasted about seven minutes and included over 100 storage account deletion attempts. Most targeted Azure Storage accounts were deleted, although resource locks and account-level deletion protection stopped several attempts.

The actor also deleted an Azure Key Vault, a Function App, and an App Service plan. Parallel attempts to delete several Azure SQL databases failed because the requests used an unsupported API version. About 30 minutes after the destructive activity ended, the same identity sent more than 30 successful ListKeys requests to retrieve storage account access keys.

Possible entry point and defenses

Microsoft could not establish exactly how the service principal was compromised. Its client ID, client secret, and tenant ID had previously appeared in plaintext in a public GitHub issue posted by an employee of the affected organization. The issue was edited, but the secret remained in its public edit history. Researchers could not confirm that this credential enabled the observed attack.

Microsoft assessed the resource deletion, attacks on recovery controls, and key collection as consistent with a ransomware-aligned objective. It observed neither a ransom note nor confirmed data exfiltration in this incident. The company recommends immediately revoking or rotating exposed secrets, applying least privilege to workload identities, and independently protecting backup and recovery resources.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.