Executive Summary
In June 2026, the AI-driven threat actor JADEPUFFER (tracked as Storm-3168 by Microsoft) conducted an 18-hour destructive campaign against Microsoft Azure infrastructure using compromised service principals. The attack involved systematic reconnaissance of Azure resources followed by destructive operations targeting Storage Accounts, SQL databases, Key Vaults, Function Apps, and Virtual Machines. Over 300 read operations were conducted during enumeration, followed by more than 150 destructive operations in just 35 minutes, successfully deleting most targeted Azure Storage accounts.
This incident represents a significant evolution in ransomware operations, as JADEPUFFER became the first threat actor to conduct end-to-end attacks orchestrated by large language models. The attack demonstrates how AI can autonomously coordinate complex post-compromise operations across cloud environments with unprecedented speed and scale, marking a new era of autonomous cyber threats.
Why This Matters Now
AI-orchestrated attacks are rapidly emerging as a critical threat vector, with JADEPUFFER proving that autonomous systems can execute sophisticated multi-cloud campaigns. Organizations must urgently adapt their defense strategies to counter AI-driven adversaries that operate at machine speed and scale.
Attack Path Analysis
JADEPUFFER/Storm-3168 exploited exposed service principal credentials found in public GitHub repositories to gain initial access to Azure environments. The threat actor escalated privileges using compromised service principals with broad administrative permissions, conducted extensive reconnaissance across Azure resources for 16+ hours, established command and control through automated scripting and AI-orchestrated operations, and executed destructive impact operations targeting storage accounts, databases, and critical infrastructure components over a 7-minute window.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actor obtained Azure service principal credentials (client ID, client secret, tenant ID) that were previously exposed in plaintext in public GitHub issue history by an employee of the targeted organization
Related CVEs
CVE-2025-3248
CVSS 9.8A remote code execution vulnerability in Langflow allows attackers to execute arbitrary code via improper input validation.
Affected Products:
Langflow Langflow – < patched version
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Unsecured Credentials: Credentials In Files
Cloud Infrastructure Discovery
Account Discovery: Cloud Account
Cloud Service Discovery
Data Destruction
Service Stop
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
Digital Operational Resilience Act (DORA) – Backup Policies and Recovery Procedures
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
ISO 27001:2022 – Configuration Management
Control ID: A.8.9
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical exposure to AI-orchestrated ransomware targeting cloud infrastructure, service principals, and development environments with sophisticated automated attack chains.
Information Technology/IT
High risk from Storm-3168 agentic attacks exploiting Azure environments, compromised service principals, and cloud resources through automated LLM-driven operations.
Financial Services
Severe threat from JADEPUFFER ransomware targeting cloud databases, storage accounts, and key vaults with compliance implications for data protection.
Health Care / Life Sciences
Major vulnerability to AI-driven destructive attacks on Azure infrastructure affecting patient data storage, backup systems, and HIPAA compliance requirements.
Sources
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resourceshttps://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.htmlVerified
- Storm-3168: Agentic-driven cloud attacks using compromised service principalshttps://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/Verified
- AI Agent Exploits Langflow RCE to Deploy Ransomwarehttps://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.htmlVerified
- New ENCFORGE Ransomware Targets AI Infrastructurehttps://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Azure environment compromise by constraining lateral movement paths and segmenting access to critical resources. The attacker's ability to conduct extensive reconnaissance and execute destructive operations across multiple subscriptions would likely be limited through identity-aware segmentation and controlled resource access.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial credential compromise may still occur, but subsequent access to cloud resources would likely be constrained through identity-aware access controls and segmented network paths that limit the scope of reachable assets
Control: Zero Trust Segmentation
Mitigation: Administrative privilege escalation across multiple subscriptions would likely be constrained through segmented access boundaries that limit cross-subscription resource visibility and control, reducing the attacker's administrative reach
Control: East-West Traffic Security
Mitigation: Cross-subscription reconnaissance and resource enumeration would likely be significantly constrained through workload isolation and microsegmentation policies that limit visibility between resource groups and subscription boundaries
Control: Multicloud Visibility & Control
Mitigation: Coordinated automated operations across multiple service principals would likely be detected and constrained through centralized visibility that monitors cross-principal activity patterns and implements behavioral controls on resource access timing
Control: Egress Security & Policy Enforcement
Mitigation: Credential harvesting from configuration stores and Key Vaults would likely be constrained through controlled access policies that limit data retrieval operations and implement egress monitoring for sensitive credential data
While some destructive operations may still occur within accessible segments, the scope of deletable resources would likely be significantly reduced through segmentation boundaries that isolate critical infrastructure components from compromised workloads
Impact at a Glance
Affected Business Functions
- Cloud Infrastructure Services
- Data Storage and Backup Operations
- Application Development and Deployment
- Database Management Systems
Estimated downtime: 7 days
Estimated loss: $500,000
Azure Storage Accounts, SQL databases, Key Vaults containing sensitive configuration data, credentials, and application secrets. Multiple storage accounts were successfully deleted along with backup and recovery resources, compromising data availability and business continuity.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege access controls to limit service principal permissions and prevent broad administrative access across Azure resources
- • Deploy Multicloud Visibility & Control capabilities to detect anomalous automation patterns and repeated enumeration activities across cloud environments
- • Enable Egress Security & Policy Enforcement to monitor and control outbound communications from compromised service principals and prevent unauthorized data exfiltration
- • Establish Threat Detection & Anomaly Response to identify AI-orchestrated attack patterns and coordinated operations across multiple service principals
- • Implement comprehensive credential governance and monitoring to detect exposed credentials in public repositories and rotate compromised service principal secrets immediately



