Skip to main content

JadePuffer agentic AI attacks target Azure, destroy cloud resources

0
High
Published: 09/28/2026 (09/28/2026, 15:49:27 UTC)
Source: Bleeping Computer

Description

The JadePuffer ransomware operator conducts agent-driven attacks targeting Microsoft Azure tenants. These attacks automate reconnaissance, credential theft, lateral movement, and destruction of cloud resources, including storage accounts, Key Vaults, Function Apps, Virtual Machines, and App Services. The attacker used compromised service principals to access and delete resources, removing backup protections to hinder recovery. Attempts to delete Azure SQL databases failed due to unsupported API versions. The threat actor is tracked as Storm-3168. Microsoft recommends activating cloud workload protections, auditing for exposed credentials, and enforcing least-privilege permissions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 16:02:59 UTC

Technical Analysis

JadePuffer is a ransomware operator leveraging AI-driven agents to automate attacks against Azure cloud environments. The attacks involve reconnaissance, credential theft, lateral movement, persistence, and destructive operations targeting core Azure resources such as storage accounts, Key Vaults, Function Apps, VMs, and App Services. Microsoft observed that the attacker used two compromised service principals within the same tenant to perform discovery and destructive actions. The attacker removed Azure Site Recovery locks to prevent restoration. Attempts to delete Azure SQL databases and remove recovery locks failed due to unsupported API usage. Credential exposure on a public GitHub issue likely facilitated initial access. The attacker’s operational pattern suggests potential ransomware extortion, though no financial demands or confirmed data theft were reported. Microsoft recommends cloud workload protection, secret scanning, and least-privilege RBAC enforcement.

Potential Impact

The attacks resulted in the deletion of over 100 Azure Storage accounts and destruction of other critical cloud resources, causing significant data loss and service disruption. Backup and recovery protections were disabled, complicating restoration efforts. Although attempts to delete Azure SQL databases failed, the broad targeting of multiple resource types indicates a wide destructive impact. Credential theft and lateral movement within the tenant increased the attacker's control and persistence. No confirmed data theft or ransom demands were reported in the observed incidents.

Defensive Guidance

Microsoft recommends activating cloud workload protections to detect and prevent such attacks. Administrators should audit for exposed credentials, especially in public repositories, and remove any found secrets. Azure Role-Based Access Control (RBAC) permissions should be reviewed and adjusted to follow least-privilege principles to limit the impact of compromised identities. Resource locks and backup protections should be enabled and monitored to prevent unauthorized deletion. Since this is a cloud-hosted service, Microsoft manages platform-level security, but tenant-level security hygiene is critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6aba8fa9f7a7c54106e47698

Added to database: 09/28/2026, 16:02:49 UTC

Last enriched: 09/28/2026, 16:02:59 UTC

Last updated: 09/28/2026, 17:34:02 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses