The cyber threat group known as JADEPUFFER has been actively involved in conducting destructive operations within Microsoft Azure environments by exploiting compromised service principals. This activity, tracked by Microsoft under the designation Storm-3168, represents a significant evolution in the group’s attack strategies. The attack occurred in early June 2026, spanning approximately 18 hours.
Compromised Service Principals and Targeted Resources
Microsoft’s researchers, Yossi Weizman and Tushar Mudi, along with the Security Research team, have reported that the attack involved the compromise of service principals, which were then used to target various Azure components. These components included Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, and App Services. The attack’s destructive nature highlights the group’s ability to infiltrate and disrupt critical cloud-based resources.
JADEPUFFER, initially identified by Sysdig, has been associated with pioneering ransomware operations facilitated by large language models (LLM). The group exploited a known vulnerability in Langflow (CVE-2025-3248) to infiltrate systems, gather credentials, penetrate networks, encrypt service configuration files, and leave ransom demands for Bitcoin payments. This attack was further advanced with the use of a Go-based ransomware variant named ENCFORGE, targeting AI infrastructure and various file extensions.
Advanced Techniques and AI-Driven Orchestration
The use of ENCFORGE, designed specifically for AI environments, allowed the attackers to scan for nearly 180 file extensions, including those related to AI model checkpoints and Mac-specific files. According to Sysdig, the attack was characterized by an autonomous agent that systematically harvested credentials, moved laterally within the network, and maintained persistence, all while articulating its objectives.
Microsoft’s analysis detailed two compromised service principals linked to the same Azure tenant. The first was used for reconnaissance and resource discovery, while the second facilitated destructive actions and credential collection. Enumeration activities focused on Azure Virtual Machines, resource groups, and subscriptions, with over 300 read operations conducted during the attack period.
Impact and Defensive Measures
The operation culminated in numerous destructive or credential-collection actions, including attempts to delete over 100 storage accounts within a brief span. Although most targeted Azure Storage accounts were successfully deleted, some were protected by independent safeguards, such as resource locks and deletion protection measures, which thwarted the attackers’ efforts.
Microsoft indicated that the compromised service principal’s credentials, including the client ID, secret, and tenant ID, were inadvertently exposed in a public GitHub issue by an organization employee. Despite the secret’s removal, the information remained accessible through the platform’s edit history.
Ongoing investigations by Microsoft have detected further probing activities from Storm-3168 related infrastructure, suggesting that the attacks may be automated. The attackers’ ultimate goal seems to align with ransomware motives, aiming to disable recovery capabilities, although no ransom note or data exfiltration was confirmed.
As threat actors increasingly leverage AI to coordinate complex operations across cloud environments, cybersecurity defenses must similarly evolve to counteract these sophisticated threats. The JADEPUFFER case underscores the pressing need for robust security measures and the adoption of AI-driven defense mechanisms to protect against such advanced cyber threats.
