Executive Summary
In June 2026, Microsoft identified Storm-3168 (JADEPUFFER), the first documented agentic ransomware operation, conducting extensive destructive attacks against Azure cloud environments using compromised service principals. The threat actor performed automated resource destruction across Azure Storage Accounts, SQL databases, Key Vaults, and Virtual Machines while attempting to disable recovery mechanisms and collect credentials for potential future exfiltration. The attack demonstrated sophisticated automation with coordinated operations across multiple compromised identities, completing over 150 destructive operations in just 35 minutes.
This incident represents a critical evolution in ransomware tactics, showcasing how AI-orchestrated attacks enable threat actors to coordinate complex post-compromise operations across cloud environments with unprecedented speed and scale, fundamentally changing the threat landscape for cloud security.
Why This Matters Now
Storm-3168 marks the emergence of AI-driven ransomware operations that can automate complex cloud attacks at machine speed, requiring organizations to immediately reassess their cloud security posture and implement AI-powered defensive capabilities to match this new threat sophistication.
Attack Path Analysis
Storm-3168 conducted an agentic-driven cloud attack by exploiting exposed service principal credentials from GitHub to compromise Azure environments. The attack progressed through automated reconnaissance across multiple subscriptions, leveraging existing RBAC permissions for privilege maintenance, and executing coordinated destructive operations targeting storage accounts, databases, and recovery infrastructure while collecting credentials for potential future exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actor leveraged exposed service principal credentials (client ID, client secret, tenant ID) that were previously disclosed in plaintext in a public GitHub issue, with credentials remaining accessible through edit history even after redaction
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Cloud Service Discovery
Unsecured Credentials: Private Keys
Data Destruction
Inhibit System Recovery
Exploit Public-Facing Application
Account Discovery: Cloud Account
Data from Cloud Storage Object
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Processes and mechanisms for limiting access to system components and cardholder data environments
Control ID: 7.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT risk management framework
Control ID: Article 11
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Identity
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
ISO 27001 – User access provisioning
Control ID: A.9.2.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Storm-3168's agentic ransomware targeting Azure service principals creates severe risks for IT providers managing multi-tenant cloud infrastructures and client workloads.
Financial Services
Compromised service principals enabling automated resource destruction and credential collection pose critical threats to financial institutions' cloud-hosted trading systems and databases.
Health Care / Life Sciences
Azure-focused destructive operations targeting storage accounts and SQL databases threaten HIPAA-compliant patient data systems and backup recovery mechanisms.
Computer Software/Engineering
GitHub credential exposure and automated cloud resource destruction particularly impact software development organizations using Azure DevOps and cloud-native application architectures.
Sources
- Storm-3168: Agentic-driven cloud attacks using compromised service principalshttps://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/Verified
- JADEPUFFER: Agentic ransomware for automated database extortionhttps://sysdig.com/blog/jadepuffer-agentic-ransomware/Verified
- Microsoft Defender XDR Threat Analytics - Storm-3168https://security.microsoft.com/threatanalyticsVerified
- Azure Resource Manager security best practiceshttps://docs.microsoft.com/en-us/azure/azure-resource-manager/management/security-controlsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained Storm-3168's multi-subscription lateral movement and destructive operations by implementing identity-aware segmentation and controlled egress policies. The attack's blast radius would likely have been reduced through workload isolation and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access policies would likely have restricted the compromised service principal's initial authentication scope and limited reachability to critical cloud resources based on behavioral analysis.
Control: Zero Trust Segmentation
Mitigation: Micro-segmentation policies would likely have constrained the service principals' privilege scope by enforcing granular access boundaries that limit cross-subscription operations regardless of assigned RBAC roles.
Control: East-West Traffic Security
Mitigation: Inter-service communication controls would likely have limited the attackers' ability to traverse between subscriptions and enumerate resources by enforcing strict east-west traffic policies.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and control mechanisms would likely have detected and constrained the coordinated multi-token operations by identifying abnormal automation patterns across cloud services.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have limited the attackers' ability to extract sensitive credentials and data by restricting outbound communication paths and monitoring key retrieval operations.
While some destructive operations may still have occurred, the scope would likely have been significantly reduced with critical backup and recovery infrastructure potentially remaining protected through segmented access controls.
Impact at a Glance
Affected Business Functions
- Cloud Infrastructure Management
- Data Storage and Backup
- Application Services
- Database Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Azure Storage Account access keys, Key Vault secrets, SQL database credentials, and potential access to backup and recovery data. The threat actor successfully retrieved 30+ storage account access keys which could provide access to sensitive organizational data stored in Azure Storage Accounts including Site Recovery related storage.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege identity policies to prevent compromised service principals from accessing broad Azure resources across subscriptions
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized credential exfiltration and suspicious ListKeys operations to external destinations
- • Enable Multicloud Visibility & Control with centralized policy enforcement to detect anomalous automation patterns and repeated malformed requests across cloud environments
- • Strengthen East-West Traffic Security to monitor and control service-to-service communications between Azure resources during lateral movement activities
- • Activate Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous detection of agentic AI-driven attack patterns and shadow AI risks



