The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In June 2026, the AI-driven threat actor JADEPUFFER (tracked as Storm-3168 by Microsoft) conducted an 18-hour destructive campaign against Microsoft Azure infrastructure using compromised service principals. The attack involved systematic reconnaissance of Azure resources followed by destructive operations targeting Storage Accounts, SQL databases, Key Vaults, Function Apps, and Virtual Machines. Over 300 read operations were conducted during enumeration, followed by more than 150 destructive operations in just 35 minutes, successfully deleting most targeted Azure Storage accounts.

This incident represents a significant evolution in ransomware operations, as JADEPUFFER became the first threat actor to conduct end-to-end attacks orchestrated by large language models. The attack demonstrates how AI can autonomously coordinate complex post-compromise operations across cloud environments with unprecedented speed and scale, marking a new era of autonomous cyber threats.

Why This Matters Now

AI-orchestrated attacks are rapidly emerging as a critical threat vector, with JADEPUFFER proving that autonomous systems can execute sophisticated multi-cloud campaigns. Organizations must urgently adapt their defense strategies to counter AI-driven adversaries that operate at machine speed and scale.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The service principal credentials (client ID, client secret, and tenant ID) were exposed in plaintext in a public GitHub issue by an employee, and remained accessible through the public edit history even after removal.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Azure environment compromise by constraining lateral movement paths and segmenting access to critical resources. The attacker's ability to conduct extensive reconnaissance and execute destructive operations across multiple subscriptions would likely be limited through identity-aware segmentation and controlled resource access.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial credential compromise may still occur, but subsequent access to cloud resources would likely be constrained through identity-aware access controls and segmented network paths that limit the scope of reachable assets

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Administrative privilege escalation across multiple subscriptions would likely be constrained through segmented access boundaries that limit cross-subscription resource visibility and control, reducing the attacker's administrative reach

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-subscription reconnaissance and resource enumeration would likely be significantly constrained through workload isolation and microsegmentation policies that limit visibility between resource groups and subscription boundaries

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Coordinated automated operations across multiple service principals would likely be detected and constrained through centralized visibility that monitors cross-principal activity patterns and implements behavioral controls on resource access timing

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Credential harvesting from configuration stores and Key Vaults would likely be constrained through controlled access policies that limit data retrieval operations and implement egress monitoring for sensitive credential data

Impact (Mitigations)

While some destructive operations may still occur within accessible segments, the scope of deletable resources would likely be significantly reduced through segmentation boundaries that isolate critical infrastructure components from compromised workloads

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Services
  • Data Storage and Backup Operations
  • Application Development and Deployment
  • Database Management Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Azure Storage Accounts, SQL databases, Key Vaults containing sensitive configuration data, credentials, and application secrets. Multiple storage accounts were successfully deleted along with backup and recovery resources, compromising data availability and business continuity.

Recommended Actions

  • • Implement Zero Trust Segmentation with least privilege access controls to limit service principal permissions and prevent broad administrative access across Azure resources
  • • Deploy Multicloud Visibility & Control capabilities to detect anomalous automation patterns and repeated enumeration activities across cloud environments
  • • Enable Egress Security & Policy Enforcement to monitor and control outbound communications from compromised service principals and prevent unauthorized data exfiltration
  • • Establish Threat Detection & Anomaly Response to identify AI-orchestrated attack patterns and coordinated operations across multiple service principals
  • • Implement comprehensive credential governance and monitoring to detect exposed credentials in public repositories and rotate compromised service principal secrets immediately

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image