[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYEY0K3y3LrXikxmGOnKvJ1AyDeLO-eTfHLUNNN86sNI":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"f9e03db5-5b4d-4d3e-a900-56478532af8e","JadePuffer agentic AI attacks target Azure, destroy cloud resources","jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources-178f19","The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]","The JadePuffer ransomware operator, tracked as Storm-3168 by Microsoft, is using AI agents to automate attacks against Azure tenants. These attacks involve reconnaissance, credential theft, and the destruction of cloud resources like storage accounts, Key Vaults, and virtual machines. While the attackers aim to make recovery difficult, some protections like Azure resource locks prevented complete data loss in observed incidents.","JadePuffer ransomware operator targets Azure tenants with agentic AI attacks, destroying cloud resources.","JadePuffer agentic AI attacks target Azure, destroy cloud resources By Bill Toulas September 28, 2026 11:49 AM 0 The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption. Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge. Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts. The destructive stage lasted seven minutes and targeted more than 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services. Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections. Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals - security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources. Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other \"performed discovery, destructive operations, and credential collection.\" Timeline of observed attacksSource: Microsoft The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an effort to make restoration more difficult. This operational pattern could further support ransomware extortion, although Microsoft did not report anything about financial demands and didn’t confirm data theft in the observed cases. According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed. “The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type,” Microsoft said. Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded. Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks. The researchers recommend several mitigation steps and guidance for system administrators, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Cloudflare fixes Containers cross-tenant flaw exposing customer dataShinyHunters hacked Clop leak site using Grav CMS path traversal flawShinyHunters hacks Clop leak site, threatens to extort ransomware gangCISA: Ransomware gangs now exploiting critical TeamCity flawRyuk ransomware member sentenced to 24 months in prison","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fjadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F01\u002FAzure.jpg","2026-09-28T15:49:27+00:00","2026-09-28T18:00:12.032316+00:00",9,[18,21,23,26,28,31],{"name":19,"type":20},"JadePuffer","threat_actor",{"name":22,"type":20},"Storm-3168",{"name":24,"type":25},"Azure","product",{"name":27,"type":25},"EncForge",{"name":29,"type":30},"AI agents","technology",{"name":32,"type":30},"service principals","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,41,46,51],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57,61,64,67,70],{"type":58,"value":59,"context":60},"mitre_attack","T1078.004","Use of compromised service principals for authentication to Azure",{"type":58,"value":62,"context":63},"T1531","Account Access: Abuse Elevation Control Mechanism (deletion of Azure resources)",{"type":58,"value":65,"context":66},"T1087.004","Account Discovery: Cloud Account",{"type":58,"value":68,"context":69},"T1557","Credential Dumping: Credential API",{"type":58,"value":71,"context":72},"T1490","Inhibit System Recovery (removal of backup and recovery protections)"]