News / Cybersecurity
JADEPUFFER and Storm-3168: How Compromised Azure Identities Wiped Resources in 18 Hours Published on 28 September 2026 by Christ-loisele (4 min read)
A group of cybercriminals linked to JADEPUFFER exploited compromised service principals in Azure to delete storage accounts, databases, and vaults in June 2026. The attack, documented under the name Storm-3168, highlights critical gaps in cloud identity management and secret exposure.
Video: Storm-3168: AI Agent Guts an Azure Tenant (Threadlinqs, YouTube)
A Destructive Campaign Orchestrated via Stolen Identities
Researchers from Microsoft and Sysdig attributed to JADEPUFFER, tracked under the code name Storm-3168 , a series of attacks against Azure environments in June 2026. The group used two compromised service principals belonging to the same Azure tenant: one for reconnaissance (over 300 read operations in 15 hours and 30 minutes), the other for destructive actions. In 35 minutes, this second identifier executed over 150 operations, including the deletion of 100 Azure storage accounts , a key vault (Key Vault), a function app, and an application service plan, according to Microsoft and Sysdig analyses.
The attack targeted resources protected by recovery locks or deletion safeguards, but most unlocked storage accounts were erased. Attempts to delete SQL databases failed due to an unsupported API version , while access keys for 30 storage accounts were retrieved via ListKeys requests after the destructive operations. No ransom note or data exfiltration was observed, confirming a purely destructive objective.
No single technique was sophisticated, but their automated sequence exploited neglected internet-facing infrastructures
Illustration: Lawing Tech
An Initial Access Flaw and Critical Secret Exposure
The intrusion began by exploiting the CVE-2025-3248 vulnerability in a Langflow instance, as documented by Sysdig. Once access was gained, the attackers used the MySQL AES_ENCRYPT() function before deploying a Go-based ransomware named ENCFORGE against the same target. However, the primary attack vector stemmed from the exposure of a service principal : its client ID, secret, and tenant ID had been published in a public GitHub issue by an employee of the victim organization, according to Microsoft.
Researchers noted that these compromised credentials remained usable as long as they were not revoked or changed , even after the issue was deleted. Microsoft also detected repeated probes from infrastructures linked to Storm-3168 against Azure App services since early 2026, targeting WordPress endpoints, PHP-CGI, and Langflow specifically.
An Agentic Model, But Not Necessarily Artificial
Sysdig qualifies JADEPUFFER as the first documented agentic ransomware operation , capable of reasoning about its targets, harvesting and reusing credentials, moving laterally, and destroying databases. However, Microsoft clarifies that the observed automation does not rely on decisions made by artificial intelligence, but on a preconfigured infrastructure set up by humans. "A human always set up the operation and provisioned the infrastructure," reminds Michael Clark, director of threat research at Sysdig.
Analysis of the logs reveals a coordinated sequence: after 90 minutes of reconnaissance, the second primary service enumerated virtual machines and resource groups in 5 seconds , then launched a wave of deletions in 7 minutes. Researchers note that no individual technique was sophisticated , but their automated sequence exploited neglected internet-facing infrastructures.
What this changes here: risks for businesses and administrations in West Africa
For Beninese or West African businesses and administrations using Microsoft Azure , this attack highlights three major risks:
Cloud identity exposure : Secrets like client secrets or tenant IDs accidentally published on public platforms (GitHub, forums) could be recovered by groups like Storm-3168. Systematic rotation of credentials and real-time leak monitoring would become critical. Dependence on protective safeguards : Storage accounts and databases not secured with Azure Resource Locks or deletion protections remain vulnerable to mass deletions. Administrations using Azure to store sensitive data (civil status, health, finances) should audit their configurations.Automation of attacks : Even without advanced AI, tools like ENCFORGE or Python scripts (such as the user agent python-requests/2.34.2 observed) can chain destructive actions within minutes. Strict segmentation of Azure roles (e.g., limiting Contributor access to essential resources) would reduce the impact.Finally, the initial target, a vulnerability in Langflow , reminds us that poorly configured open-source or SaaS tools can serve as entry points. Organizations should prioritize updating dependencies and regularly scanning their environments to detect vulnerabilities like CVE-2025-3248, still exploitable a year after its publication.
Sources