Storm-3168 executed a swift and destructive attack on an Azure environment by exploiting compromised cloud identities. This incident underscores the severe implications of stolen application credentials, granting attackers extensive control over data and services. The attack, connected to JADEPUFFER ransomware activities, highlights the rising threat posed by automated cloud assaults.
Uncovering the Attack
Investigators identified two compromised service principals within a single tenant. One principal mapped the environment while the other was responsible for resource destruction and storage key collection. The attacker, tracked by Microsoft as Storm-3168, targeted various Azure components, including Storage accounts, SQL databases, and recovery controls.
Microsoft’s report, shared with Cyber Security News, indicated no confirmed ransom demands or data theft, yet the attack’s characteristics suggest a focus on extortion. The breach highlights vulnerabilities that can arise long before destructive actions occur, such as exposed credentials on public platforms like GitHub.
Details of the Azure Breach
In June 2026, the initial compromised identity conducted over 300 read operations across Azure resources, mapping virtual machines and subscriptions. Shortly after, a second identity swiftly scanned resources and began probing App Service configurations. The destructive operations commenced less than a minute after these reconnaissance activities.
Over seven minutes, Storm-3168 attempted to delete more than 100 storage accounts, successfully removing most. Attempts to delete SQL databases were thwarted by unsupported API versions, showcasing the importance of independent safeguards like resource locks.
Security Implications and Recommendations
The simultaneous use of multiple identities and tokens for deletion and key collection suggests coordinated automation. Organizations must promptly revoke exposed credentials, investigate their use, and adhere to the principle of least privilege for identities. An Azure Arc report further emphasizes the risks of accessible deployment secrets.
Administrators are advised to restrict access to backups, monitor changes to recovery controls, and review identity permissions regularly. Security teams should be vigilant for unusual resource discovery and deletion activities, as highlighted in reports on Key Vault access risks.
Indicators of compromise (IoCs) were identified, including specific IP addresses related to malicious Azure Resource Manager requests. These indicators are crucial for threat intelligence and incident response.
To enhance incident response, organizations are encouraged to integrate threat intelligence tools, cutting down the investigation time for security operations centers (SOCs) and improving overall cyber resilience.
