The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In June 2026, Microsoft identified Storm-3168 (JADEPUFFER), the first documented agentic ransomware operation, conducting extensive destructive attacks against Azure cloud environments using compromised service principals. The threat actor performed automated resource destruction across Azure Storage Accounts, SQL databases, Key Vaults, and Virtual Machines while attempting to disable recovery mechanisms and collect credentials for potential future exfiltration. The attack demonstrated sophisticated automation with coordinated operations across multiple compromised identities, completing over 150 destructive operations in just 35 minutes.

This incident represents a critical evolution in ransomware tactics, showcasing how AI-orchestrated attacks enable threat actors to coordinate complex post-compromise operations across cloud environments with unprecedented speed and scale, fundamentally changing the threat landscape for cloud security.

Why This Matters Now

Storm-3168 marks the emergence of AI-driven ransomware operations that can automate complex cloud attacks at machine speed, requiring organizations to immediately reassess their cloud security posture and implement AI-powered defensive capabilities to match this new threat sophistication.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Storm-3168 is the first documented agentic ransomware that uses AI to automate complex cloud attacks, enabling coordinated destructive operations across Azure environments at unprecedented speed and scale.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained Storm-3168's multi-subscription lateral movement and destructive operations by implementing identity-aware segmentation and controlled egress policies. The attack's blast radius would likely have been reduced through workload isolation and east-west traffic enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware access policies would likely have restricted the compromised service principal's initial authentication scope and limited reachability to critical cloud resources based on behavioral analysis.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Micro-segmentation policies would likely have constrained the service principals' privilege scope by enforcing granular access boundaries that limit cross-subscription operations regardless of assigned RBAC roles.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Inter-service communication controls would likely have limited the attackers' ability to traverse between subscriptions and enumerate resources by enforcing strict east-west traffic policies.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility and control mechanisms would likely have detected and constrained the coordinated multi-token operations by identifying abnormal automation patterns across cloud services.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have limited the attackers' ability to extract sensitive credentials and data by restricting outbound communication paths and monitoring key retrieval operations.

Impact (Mitigations)

While some destructive operations may still have occurred, the scope would likely have been significantly reduced with critical backup and recovery infrastructure potentially remaining protected through segmented access controls.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Data Storage and Backup
  • Application Services
  • Database Operations
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Azure Storage Account access keys, Key Vault secrets, SQL database credentials, and potential access to backup and recovery data. The threat actor successfully retrieved 30+ storage account access keys which could provide access to sensitive organizational data stored in Azure Storage Accounts including Site Recovery related storage.

Recommended Actions

  • • Implement Zero Trust Segmentation with least privilege identity policies to prevent compromised service principals from accessing broad Azure resources across subscriptions
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized credential exfiltration and suspicious ListKeys operations to external destinations
  • • Enable Multicloud Visibility & Control with centralized policy enforcement to detect anomalous automation patterns and repeated malformed requests across cloud environments
  • • Strengthen East-West Traffic Security to monitor and control service-to-service communications between Azure resources during lateral movement activities
  • • Activate Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous detection of agentic AI-driven attack patterns and shadow AI risks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image