Skip to content
MediumNews

JadePuffer agentic AI attacks target Azure, destroy cloud resources

Published
Record updated
View JSON

Summary

The JadePuffer ransomware operator, tracked by Microsoft as Storm-3168, is using AI agents to automate attacks against Azure tenants, from reconnaissance and credential theft to destruction of resources. In two June attacks, the actor used two compromised service principals from the same tenant to map cloud resources, retrieve storage account keys and delete more than 100 Azure Storage accounts within seven minutes, while some accounts survived because of Azure resource locks and storage account-level protections. Microsoft could not determine how initial access occurred, though credentials for one service principal appeared in a public GitHub issue before the attacks.

Mitigation

The researchers recommend activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.