Microsoft has identified the cybercriminal group Storm-3168, associated with the JadePuffer agentic ransomware, hijacking Azure service principals to conduct extensive cloud resource reconnaissance, destruction, and credential theft over an 18-hour period. The attackers deleted numerous Azure Storage accounts, Key Vaults, and other resources while targeting backup and recovery mechanisms, suggesting preparation for a ransomware attack, although no ransom demand or confirmed data exfiltration occurred. This incident highlights risks from exposed credentials and the potential for automated, AI-driven ransomware operations within cloud environments.
JadePuffer Crims Hijacked Azure Identities and Used Them to Blow up Cloud Resources

