Microsoft Links Azure Destruction Campaign to JADEPUFFER Threat Group
Microsoft announced that a coordinated, Azure‑focused attack campaign has been traced to the threat actor known as JADEPUFFER, which the firm catalogs under the identifier Storm‑3168. The campaign, which surfaced in recent weeks, targeted a range of Azure tenants by exploiting compromised service principals to gain a foothold and then systematically dismantle cloud resources.
According to the company, the intrusion began when the attackers obtained legitimate service principal credentials—digital identities that allow applications to access Azure services without human interaction. By hijacking these identities, the group could move laterally across the victim’s environment, enumerate storage accounts, and identify other critical components without triggering typical alarm thresholds.
Once the attackers mapped the landscape, they proceeded to delete Azure Storage accounts and associated application elements. In several instances, the deletions were timed to coincide with backup windows, effectively crippling recovery attempts and prolonging downtime for affected organizations. The destructive actions extended beyond mere data loss; they also disrupted the operational pipelines that depend on those storage resources.
In addition to the overt sabotage, the campaign included credential harvesting. The stolen service principal keys and other cloud authentication tokens were exfiltrated, giving the threat actors the ability to re‑enter the compromised tenants or pivot to other cloud services. This dual approach—combining data destruction with credential theft—heightens the risk of follow‑on attacks and long‑term espionage.
Microsoft’s security teams responded by publishing detailed detection guidance, revoking compromised credentials, and working directly with impacted customers to restore services. The firm also emphasized the importance of strict privilege management, recommending that organizations enforce least‑privilege principles for service principals, rotate keys regularly, and monitor anomalous API calls through Azure Activity Log and Azure Sentinel.
Analysts note that the JADEPUFFER operation underscores a broader shift toward supply‑chain style attacks on cloud infrastructure, where legitimate identities are weaponized against their owners. As more enterprises migrate workloads to Azure, experts expect heightened scrutiny of identity management practices and a push for automated credential rotation. Microsoft has pledged continued monitoring and will update its threat intelligence as new indicators emerge, urging the security community to stay vigilant against similar tactics.
Comments (0)
Be the first to comment.
Join the discussion