Microsoft Security Research has pulled back the curtain on a chilling escalation in ransomware tradecraft: an Azure-focused destruction campaign carried out by JADEPUFFER, the threat actor Microsoft tracks as Storm-3168, using compromised service principals and what appears to be scripted, near-instantaneous coordination between identities.
The findings, published by Microsoft’s threat intelligence team, mark the first detailed look at Storm-3168’s cloud operations and reinforce warnings that AI-orchestrated attacks are no longer theoretical.
The intrusion unfolded with clinical efficiency. One compromised service principal spent roughly 15.5 hours quietly mapping the victim’s Azure estate, executing over 300 successful read operations across virtual machines, subscriptions, and resource groups.
Storm-3168 Hackers Use AI-Automated Attacks
Ninety minutes later, a second service principal sharing the same network fingerprint and the telltale python-requests/2.34.2 user agent swept through two subscriptions in just five seconds, a speed that points to scripted automation rather than manual operator activity.
Sixteen hours after that, the same identity probed App Service configuration stores, likely hunting for exposed credentials, before pivoting into a seven-minute deletion spree: over 100 storage account deletion attempts, most successful, alongside the removal of a Key Vault, Function App, and App Service plan tied to the same resource group.

What separates this campaign from ordinary smash-and-grab cloud attacks is its apparent intent to blunt recovery. The attacker attempted to strip Azure Site Recovery locks and Backup protection locks, safeguards specifically designed to survive a compromised identity with broad permissions.
Notably, several storage accounts survived precisely because those independent locks held firm, a detail Microsoft frames as proof that layered protections still matter even against automated adversaries.
Parallel attempts to delete Azure SQL databases failed outright, undermined by the attacker’s use of an unsupported API version a rare misstep in an otherwise disciplined operation.
Following the destruction, the same service principal pivoted to credential harvesting, issuing over 30 successful ListKeys requests against storage accounts, including ones tied to Site Recovery infrastructure.
Microsoft traces possible initial access to a service principal’s client ID, secret, and tenant ID that had been briefly posted in plaintext on a public GitHub issue by an employee.
The organization edited the post to remove the secret, but the credential remained retrievable through the issue’s public edit history, a sobering reminder that redaction is not remediation.
“Attackers now automate what used to take human operators days reconnaissance, privilege mapping, and destruction compressed into minutes means defenders no longer have the luxury of manual triage; security teams must fight machine-speed attacks with machine-speed detection,”
Microsoft’s guidance centers on treating every exposed credential as permanently compromised until explicitly rotated, even if the original post was deleted.
Organizations are urged to enforce least-privilege access for service principals, enable Defender for Cloud protections across Storage, Key Vault, SQL, and Resource Manager workloads, and harden backup infrastructure with resource locks that operate independently of the compromised identity’s permissions.
The company is also positioning its own AI-driven tools, Project Perception and Microsoft Defender for AI Security (MDASH), as the necessary countermeasure, arguing that defending against agentic attacks increasingly requires agentic defense. With Storm-3168’s operational tempo now measured in seconds rather than hours, that argument is becoming harder to dismiss.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.