
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that spy, steal credentials, and destroy core components.
The malware was revealed in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents. Automate the entire attack chainfrom espionage, credential theft, and background traffic to persistence and data encryption.
Shortly after, the company noted JadePuffer expanded her focus to AI assets, training datasets, and vector databases using a tool called EncForge.
Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, recovered storage account keys, and deleted Azure storage accounts.
The destructive phase lasted seven minutes and targeted more than 100 storage accounts, as well as key wallets, function apps, virtual machines and app services.
Although the threat actor was able to delete most of the targeted Azure Storage accounts, some were unaffected due to Azure resource locks and storage account-level protections.
Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals — security identities that enable applications, hosted services, and automation tools to authenticate to Azure and access assigned resources.
Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other was used for "reconnaissance, destructive operations, and evidence gathering."
.jpg)
Source: Microsoft
The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an attempt to make recovery more difficult.
This operational pattern may further support ransomware extortion, although Microsoft did not disclose financial demands and did not confirm data theft in observed cases.
According to the researchers, attempts to delete the Azure SQL database failed because the attacker used an unsupported API version. Attempts to remove the recovery protection lock also failed.
"The parallel targeting of Azure SQL databases and storage accounts suggests an attempt to spread the destructive effects across different data services rather than focusing on one resource type." Microsoft said.
After about half an hour of cleanup attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which were successful.
Microsoft could not determine exactly how the initial access occurred, but noted that the credentials of a service principal appeared in a public GitHub issue prior to the attacks.
The researchers recommend several mitigation measures and guidance for system administrators, including enabling cloud workload protections, checking secrets in public repositories, and reviewing Azure RBAC permissions against least-privilege principles.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks are changing, what defenders should stop doing, and how to authenticate, judge, correct, and reauthenticate at machine speed.
Save your seat.





