Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Microsoft uncovers Azure-based ransomware group hijacking service principals to wipe cloud assets

Microsoft says the Storm-3168 threat actor, linked to the JadePuffer ransomware, stole two Azure service principals and used them to delete dozens of storage accounts and other resources within an 18-hour window.

Microsoft’s security team traced a new wave of cloud-focused attacks to the Storm-3168 group, the same actors behind the JadePuffer agentic ransomware campaign. In early June, the group hijacked two Azure service principals within a single tenant, employing one to map the environment and the other to carry out destructive operations. Over a 15-hour discovery phase they performed more than 300 read operations across virtual machines, subscriptions and resource groups, gaining broad visibility.

Within the following hour they launched a rapid deletion spree, wiping over 100 storage accounts and several ancillary services such as a Key Vault, Function App and App Service plan; a few deletions were thwarted by existing resource locks. Attempts to delete Azure SQL databases failed because the wrong API version was used, and the attackers also queried storage account keys after the purge. Although the activity aligns with ransomware preparation, no ransom demand or confirmed data theft was detected.

Why it matters

The attack shows how stolen cloud identities can be weaponized to erase critical data, highlighting new ransomware risks for Azure users.

In this story

JadePufferagentic ransomwareAzure service principalscloud resource deletioncredential collectionMicrosoft securityStorm-3168ransomware tactics
Get the beta ↗