Microsoft Azure — JadePuffer Destructive AI Agent Attacks (Storm-3168) (N/A)

Publication date: September 28, 2026
Category: AI attacks (LLM/LocalAI) (realtime trigger)

Introduction

Cloud security researchers (including initial reports from Sysdig and subsequent findings by Microsoft Security Research) have documented a sophisticated campaign orchestrated by the ransomware operator known as JadePuffer, tracked by Microsoft as Storm-3168. This threat actor has targeted Microsoft Azure tenants using attacks driven by autonomous artificial intelligence agents (agentic AI) to automate the entire attack chain: from initial reconnaissance, credential theft, and lateral movement to persistence and the mass destruction of cloud resources. During the observed incidents, a seven-minute destructive cycle managed to impact over 100 storage accounts, Key Vaults, Function Apps, Virtual Machines, and App Services.

What is the JadePuffer / Storm-3168 Threat? (General Analysis)

JadePuffer represents a concerning evolution in the cyber threat landscape by integrating autonomous AI capabilities into offensive cloud operations. Unlike traditional scripts or manual step-by-step interventions, JadePuffer’s AI agents can make real-time decisions based on discovered cloud topology. The group has also expanded its focus toward AI assets, training datasets, and vector databases using specialized tooling such as EncForge.

Because there is no formal CVE identifier assigned—since the attacks abuse identity misconfigurations, leaked credentials, and native platform APIs rather than exploiting a pure software vulnerability (zero-day or patchable bug)—this is classified as a Cloud Identity Abuse and Business Logic threat (reasoned estimation based on CWE-269: Improper Privilege Management and CWE-522: Insufficiently Protected Credentials). The potential impact on infrastructure reaches critical severity (CVSS 9.0 Estimated - Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), as the attacker achieves the total destruction of service availability.

How Does It Work? (Technical Analysis)

The execution of JadePuffer attacks is orchestrated through agent-guided automated workflows:

  • Initial Access and Reconnaissance: The attacker obtains initial access via compromised credentials. In the incidents analyzed by Microsoft, credentials for one of the affected service principals had been previously leaked in a public GitHub issue. Two service principals belonging to the same tenant were used: one focused exclusively on resource discovery and reconnaissance, and a second one tasked with credential harvesting and destructive operations.
  • Agentic AI Automation: AI agents execute rapid mapping of Azure resources, identifying storage account keys, Key Vaults, and databases. The execution speed enables parallel operations that destabilize the victim’s operational environment within minutes.
  • Destructive Operations and Protection Removal: During a wipe phase lasting only seven minutes, the malware deleted over 100 storage accounts. It also attempted to disable backup and recovery protections by removing Azure Site Recovery locks (though some actions failed due to API restrictions or storage-level resource locks). Roughly thirty minutes later, the operator returned to perform over 30 storage account key retrieval requests.

Affected Systems / Environments

The impacted environments correspond directly to Microsoft Azure cloud deployments exhibiting weaknesses in Identity and Access Management (IAM) or accidental secret exposure.

  • Affected Platforms: Microsoft Azure tenants.
  • Involved Cloud Components:
    • Azure Storage accounts.
    • Azure Key Vaults.
    • Azure Function Apps.
    • Virtual Machines.
    • Azure App Services.
    • Attempted targeting of Azure SQL databases (failed due to unsupported API version).

Mitigation and Detection

Remediation

To reduce the attack surface against automated agent-driven threats in the cloud, implementing the following security measures is recommended:

  • Enable Cloud Workload Protections: Activate advanced cloud workload protection platforms (CWPP) capable of detecting anomalous behaviors in automated identities.
  • Secret and Repository Auditing: Perform continuous scans on public repositories (such as GitHub) to identify accidentally exposed service principal credentials or API keys.
  • Principle of Least Privilege (RBAC): Evaluate and restrict permissions assigned to service principals, ensuring they lack global deletion or backup management capabilities.
  • Resource Locks Utilization: Maintain active resource-level locks and Azure Site Recovery policies to prevent accidental or malicious deletion of critical backups.

Detection

Defensive security teams must actively monitor the following red flags in Azure audit logs:

  • Unusual or mass deletion activity targeting storage accounts initiated by application identities (service principals).
  • Repetitive or automated requests for storage account keys in short time intervals following destructive operations.
  • Attempts to remove recovery protection locks (Azure Site Recovery locks) or anomalous modifications to backup policies.

“The deployment of autonomous AI agents in cloud attacks accelerates the destruction cycle to mere minutes, demanding automated response capabilities and rigorous identity and privilege management from security teams.”

Wrapping Up

The JadePuffer (Storm-3168) campaign demonstrates how cybercriminals are adopting agentic artificial intelligence to orchestrate lightning-fast attacks against corporate cloud infrastructure. By automating reconnaissance and the destruction of critical resources within minutes, attackers aim to maximize extortion leverage. Defending against this new paradigm requires stringent Role-Based Access Control (RBAC), strict monitoring of application identities, and the prevention of credential leakage in public repositories.

References