Storm-3168 Abuses Leaked Azure SPNs to Delete Cloud Resources

SOC Briefing Summary :: Executive Key Takeaways
- [01]Threat actor Storm-3168 (JADEPUFFER) orchestrated an 18-hour automated cloud intrusion, attempting to destroy over 100 Azure Storage Accounts, Key Vaults, and App Services across enterprise subscriptions.
- [02]Initial access originated from Azure Service Principal credentials (client ID, secret, tenant ID) leaked in a public GitHub issue comment and recovered through revision edit history.
- [03]Enforce immutable Azure Resource Locks (CanNotDelete), enable soft-delete and purge protection on storage and Key Vaults, and mandate Workload Identity Federation to eradicate long-lived secrets.
Executive Summary
Microsoft Security Research has published a threat intelligence advisory detailing an 18-hour destructive cloud intrusion orchestrated by Storm-3168 (tracked by Sysdig as JADEPUFFER). The adversary leveraged two compromised Azure Service Principals (SPNs) possessing high-privilege Contributor access to systematically enumerate, harvest secrets from, and attempt the mass deletion of enterprise cloud infrastructure.
During a seven-minute automated deletion blitz, the threat group initiated over 100 deletion attempts against Azure Storage Accounts, alongside targeting Azure Key Vaults, Function Apps, and App Service plans. While most targeted storage accounts were wiped, critical production assets survived exclusively due to independent architectural safeguards—specifically Azure Resource Locks (CanNotDelete) and storage account-level deletion retention.
This campaign marks a critical operational evolution for JADEPUFFER, the actor previously documented by Sysdig conducting the first fully autonomous large language model (LLM) ransomware attack via Langflow (CVE-2025-3248) and distributing the Go-based ENCFORGE AI ransomware. The latest activity underscores how autonomous actors can rapidly operationalize exposed cloud identities to inflict severe operational disruption without deploying on-host malware.
Technical Vulnerability Analysis & Attack Chain

Stage 1: Credential Exposure & Unauthenticated Entry
- Root Cause: An employee of the victim organization inadvertently posted plaintext Azure Service Principal credentials—comprising
client_id,client_secret, andtenant_id—into a public GitHub issue. - Scraping Vector: Although the sensitive parameters were subsequently removed from the active issue description, the credentials remained permanently visible in the public GitHub edit revision history.
- Automated Ingestion: Storm-3168's automated infrastructure scrapers identified and indexed the exposed secret, authenticating directly to Azure Resource Manager (ARM) APIs without triggering interactive MFA or conditional access prompts.
Stage 2: Coordinated Dual-SPN Reconnaissance
Storm-3168 decoupled its post-exploitation workflow across two distinct service principals associated with the compromised tenant to divide operational overhead and bypass heuristic anomaly thresholds:
- SPN 1 (Low-and-Slow Discovery): Executed over 300 non-destructive read operations spanning 16 consecutive hours. The actor methodically mapped the organizational hierarchy, enumerating Azure Virtual Machines, subscription IDs, resource groups, and network boundaries.
- SPN 2 (Burst Discovery & Secret Extraction): Introduced 90 minutes later, SPN 2 performed aggressive, high-speed enumeration—mapping all resource groups across two full subscriptions within five seconds. SPN 2 then specifically queried Azure App Service configuration stores (
/config/appsettings/list), successfully pulling secondary application connection strings, storage keys, and embedded database credentials.
Stage 3: Safeguard Invalidation & Recovery Lock Probing
- Lock Enumeration: Prior to initiating destructive commands, the adversary inspected existing management locks (
Microsoft.Authorization/locks) applied to targeted subscriptions and resource groups. - Recovery Sabotage: The actor targeted backup-related resources and attempted to remove deletion safeguards. The explicit intent was to impair the victim organization's recovery posture prior to extortion.
Stage 4: Automated 7-Minute Resource Destruction
Following the discovery phase, SPN 2 pivoted into a hyper-automated destructive execution phase, executing more than 150 state-altering API requests within 35 minutes:
- Storage Account Purge: Over 100 storage account deletion requests (
Microsoft.Storage/storageAccounts/delete) were issued in a compressed seven-minute window. - Compute & Secrets Destruction: The actor deleted targeted Azure Key Vaults (
Microsoft.KeyVault/vaults/delete), Function Apps (Microsoft.Web/sites/delete), and App Service hosting plans. - Database Failure Vector: Storm-3168 attempted the bulk deletion of enterprise Azure SQL databases. However, all SQL database deletion calls failed execution due to the automated tooling supplying an unsupported ARM API version parameter for the target SQL resource type.
Stage 5: Defensive Safeguard Validation & Blast Radius
While dozens of unprotected storage containers and application runtimes were destroyed, enterprise safeguards decisively halted total catastrophe:
- Azure Resource Locks: Storage accounts configured with
CanNotDeletemanagement locks rejected deletion calls, maintaining data integrity despite the compromised service principal possessing Owner/Contributor role permissions. - Deletion Protection Policies: Storage account-level deletion retention policies retained container metadata, preventing unrecoverable data loss.
- Absence of Ransom Demands: Consistent with pre-attack sabotage, no active ransom note was dropped, and no large-scale data exfiltration was observed before resource purging commenced.
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | Authentication via exposed Service Principal client secret harvested from GitHub |
| Credential Access | T1552.001 | Unsecured Credentials: Cloud Secrets | Harvesting tenant ID, application ID, and client secret from public Git commit history |
| Credential Access | T1552.005 | Unsecured Credentials: Cloud Instance Metadata | Extracting database strings and API keys from Azure App Service configuration stores |
| Discovery | T1087.004 | Account Discovery: Cloud Account | SPN 1 enumerating subscriptions, role assignments, and tenant identity configurations |
| Discovery | T1526 | Cloud Service Discovery | Enumerating Azure VMs, App Services, Storage Accounts, and Key Vaults across subscriptions |
| Defense Evasion | T1578.002 | Modify Cloud Compute Infrastructure: Create Cloud Instance | Splitting reconnaissance and destructive commands across two distinct service principals |
| Defense Evasion | T1562.001 | Impair Defenses: Disable or Modify Tools | Probing and attempting removal of Azure Resource Locks and backup retention safeguards |
| Impact | T1485 | Data Destruction | Mass deletion of over 100 Azure Storage Accounts, Key Vaults, and Function Apps |
| Impact | T1490 | Inhibit System Recovery | Targeted deletion of recovery-associated storage infrastructure and protection locks |
Threat Actor Profile & Campaign Attribution
Threat Actor: Storm-3168 (tracked as JADEPUFFER by Sysdig).
Campaign Evolution:
- Phase 1 (Langflow Autonomous LLM Ransomware): JADEPUFFER was first surfaced by Sysdig in July 2026 for executing the industry's first autonomous agentic ransomware attack. An autonomous agent exploited CVE-2025-3248 in Langflow, narrated its execution trace, harvested credentials, encrypted Nacos configuration stores via MySQL
AES_ENCRYPT(), and dropped ransom demands. - Phase 2 (ENCFORGE Go Ransomware): Re-targeted identical infrastructure using compiled Go ransomware specifically crafted to target artificial intelligence assets, indexing ~180 file extensions spanning vector stores, model checkpoints, and training sets.
- Phase 3 (Storm-3168 Cloud Sabotage): In the current campaign, the group abandoned compiled on-host malware entirely. Instead, they weaponized cloud-native ARM REST APIs and exposed administrative service principals to conduct high-velocity infrastructure sabotage.
Actor Infrastructure & Behavior:
- Microsoft telemetry confirms Storm-3168 maintains scanning infrastructure continuously probing Azure App Services and public repository edit histories across enterprise tenants.
- Scripted, API-driven execution indicates high levels of automation designed to overwhelm incident response teams within minutes of credential validation.
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
- Immediate SPN Credential Revocation: Identify all service principals with secrets generated or modified during the incident window. Revoke active client secrets immediately across Microsoft Entra ID.
- Enforce Immutable Resource Locks: Apply
CanNotDeleteAzure Resource Locks at the Resource Group and Subscription level across all tier-0 assets (production storage accounts, Key Vaults, managed databases). Locks prevent accidental or malicious deletion even by tenant Owners. - Enable Storage Soft-Delete & Purge Protection: Configure container soft-delete (minimum 14-day retention) and Key Vault soft-delete with Purge Protection enabled across all Azure subscriptions.
- Migrate to Managed Identities & Workload Identity Federation: Eliminate static, long-lived client secrets for CI/CD pipelines (e.g., GitHub Actions) by enforcing Workload Identity Federation with short-lived OIDC tokens.
2. Network & Perimeter Defenses
- Service Principal Conditional Access: Enforce Conditional Access policies for Workload Identities, restricting service principal authentication to approved corporate IP ranges or trusted egress proxies.
- GitHub Secret Scanning & Push Protection: Enable GitHub Push Protection across all public and internal repositories to block commits and issue updates containing recognized cloud secret patterns.
- Audit App Service Configuration Access: Restrict read permissions on
Microsoft.Web/sites/config/appsettings/listusing granular Azure RBAC roles rather than default Contributor privileges.
3. Endpoint Detection & Hunting Query
title: Azure Service Principal Anomalous Resource Deletion Spree
id: 9b1c7e4a-2f3d-4c8e-a6a9-8d5f3b1c2e4f
status: experimental
date: 2026/09/28
author: CyberNewsAI Threat Intelligence
description: Detects a rapid succession of Azure Storage Account and Key Vault deletion operations initiated by a Service Principal identity
references:
- https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
- https://cybernewsai.com/blog/storm-3168-azure-service-principal-resource-destruction
logsource:
category: cloud
product: azure
service: activitylog
detection:
selection_identity:
Claims_appId|exists: true
selection_operations:
OperationNameValue|contains:
- 'Microsoft.Storage/storageAccounts/delete'
- 'Microsoft.KeyVault/vaults/delete'
- 'Microsoft.Web/sites/delete'
- 'Microsoft.Authorization/locks/delete'
ActivityStatusValue: 'Success'
timeframe: 10m
condition: selection_identity and selection_operations | count() > 5
level: critical
tags:
- attack.impact
- attack.t1485
- attack.t1490
- attack.defense_evasion
- attack.t1562.001
falsepositives:
- Automated DevOps cleanup pipelines or Terraform teardown scripts (filter by known deployment appId)// Microsoft Sentinel - Azure Activity Log Hunting for Storm-3168 Cloud Destruction
// Identifies rapid resource deletion bursts and sensitive configuration reads by Service Principals
let DeletionThreshold = 5;
AzureActivity
| where TimeGenerated >= ago(24h)
| where OperationNameValue in~ (
"Microsoft.Storage/storageAccounts/delete",
"Microsoft.KeyVault/vaults/delete",
"Microsoft.Web/sites/delete",
"Microsoft.Sql/servers/databases/delete",
"Microsoft.Authorization/locks/delete"
)
| extend CallerAppId = tostring(parse_json(Claims).appid)
| where isnotempty(CallerAppId)
| summarize
DeletionCount = count(),
TargetedResources = make_set(Resource),
TargetedResourceGroups = make_set(ResourceGroup),
Operations = make_set(OperationNameValue),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by CallerAppId, Caller, SubscriptionId, bin(TimeGenerated, 15m)
| where DeletionCount >= DeletionThreshold
| extend DurationMinutes = datetime_diff('minute', LastSeen, FirstSeen)
| project FirstSeen, LastSeen, CallerAppId, Caller, SubscriptionId, DeletionCount, Operations, TargetedResources, TargetedResourceGroups
| sort by DeletionCount descTargeted Azure Resource Types & Operations
| Action | Resource URI / Operation | Context |
|---|---|---|
| Secret Discovery | Microsoft.Web/sites/config/appsettings/list | Credential enumeration from App Service configurations |
| Bulk Deletion | Microsoft.Storage/storageAccounts/delete | Mass wiping of enterprise cloud storage accounts |
| Secret Destruction | Microsoft.KeyVault/vaults/delete | Deletion of cryptographic keys and service credentials |
| Compute Termination | Microsoft.Web/sites/delete | Teardown of active Function Apps and API services |
| Safeguard Removal | Microsoft.Authorization/locks/delete | Attempted deletion of Azure Resource Management locks |
| Failed Exploitation | Microsoft.Sql/servers/databases/delete | Aborted database deletion due to invalid API version param |
Compromised Identity Characteristics
| Indicator Type | Value / Pattern | Operational Context |
|---|---|---|
| Exposure Vector | Public GitHub Issue Edit History | Primary source of leaked Client ID, Secret, and Tenant ID |
| Identity Type | Azure Entra ID Service Principal | High-privilege application identities without interactive MFA |
| Privilege Level | Contributor / Owner Role Bindings | Broad tenant and subscription-level administrative scope |
| Attack Duration | ~18 Hours Total | 16 hours reconnaissance followed by 7-minute automated deletion blitz |
| Actor Tracking | Storm-3168 / JADEPUFFER | Previously attributed to Langflow LLM ransomware and ENCFORGE |
Microsoft.Web/sites/config/appsettings/listMicrosoft.Storage/storageAccounts/deleteMicrosoft.KeyVault/vaults/deleteMicrosoft.Web/sites/deleteMicrosoft.Authorization/locks/deleteStorm-3168JADEPUFFERENCFORGE// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Citrix NetScaler Hit by Twin Pre-Auth RCE Zero-Days Under Attack
Citrix confirms active zero-day exploitation of twin CVSS 9.5 RCE flaws CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. Patch immediately.

LunexStealer Abuses AMD Driver BYOVD to Blind EDR and Steal Credentials
LunexStealer deploys AMD PDFWKRNL.sys via BYOVD to zero kernel callbacks, blinding EDR before stealing browser credentials and crypto wallets across 28 panels.

GitHub Actions Re-Enabled With Active Mini Shai-Hulud Payload
Two compromised GitHub Actions re-enabled with active Mini Shai-Hulud malware exposed 15,000 repos to credential theft via uncleaned mutable release tags.