JadePuffer ransomware operator targets Azure tenants with automated AI attacks
Tech

JadePuffer ransomware operator targets Azure tenants with automated AI attacks

TechNews Editorial
TechNews EditorialSep 29, 2026 · 2 min read
Share

Why it matters

This story matters because threat actors are now deploying automated AI agents to execute multi-step cloud attacks that rapidly map, compromise, and destroy enterprise infrastructure.

The facts

  • JadePuffer ransomware operators are using AI agents to automate attacks against Azure tenants.
  • Observed attacks mapped resources and destroyed storage accounts over a seven minute window.
  • Microsoft tracks the actor as Storm-3168 and notes compromised service principals were utilized.

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. The malware emerged in July. Researchers at cloud security company Sysdig highlighted that it uses AI agents to automate the entire attack chain. This chain includes reconnaissance, credential theft, lateral movement, persistence, and data encryption. Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.

Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts. The destructive stage lasted seven minutes and targeted more than 100 storage accounts. It also targeted Key Vaults, Function Apps, Virtual Machines, and App Services. Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections.

Microsoft tracks actors as Storm-3168

Microsoft tracks the JadePuffer threat actor as Storm-3168. The company says the actor used two compromised service principals. These are security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources. Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery. The other performed discovery, destructive operations, and credential collection.

The attacker removed backup and recovery protections like Azure Site Recovery locks. This indicated an effort to make restoration more difficult. This operational pattern could further support ransomware extortion. However, Microsoft did not report anything about financial demands and did not confirm data theft in the observed cases. According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed.

A cloud database service rejects automated deletion requests while its databases and recovery protections remain intact.
Illustration: AI & Tech News

Microsoft stated that the parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type. Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded. Microsoft could not determine exactly how the initial access occurred. However, the company noted that credentials for one service principal appeared in a public GitHub issue before the attacks.

The researchers recommend several mitigation steps and guidance for system administrators. These steps include activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading