JadePuffer Crims Hijacked Azure Identities and Used Them to Blow up Cloud Resources

Microsoft has identified the cybercriminal group Storm-3168, associated with the JadePuffer agentic ransomware, hijacking Azure service principals to conduct extensive cloud resource reconnaissance, destruction, and credential theft over an 18-hour period. The attackers deleted numerous Azure Storage accounts, Key Vaults, and other resources while targeting backup and recovery mechanisms, suggesting preparation for a ransomware attack, although no ransom demand or confirmed data exfiltration occurred. This incident highlights risks from exposed credentials and the potential for automated, AI-driven ransomware operations within cloud environments.

https://www.theregister.com/security/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-cloud-resources/5299591

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top