JadePuffer Group Uses AI Agents in Destructive Azure Cloud Attacks

Microsoft tracks the threat actor as Storm-3168; ransomware operation destroys storage accounts, virtual machines, and attempts to disable recovery protections.

edit
By LineZotpaper
Published
Read Time2 min
The JadePuffer ransomware operator has escalated its tactics, using agentic AI to orchestrate destructive attacks against Microsoft Azure tenants, according to security research from Sysdig and Microsoft. In two incidents observed in June, the threat actor, tracked by Microsoft as Storm-3168, systematically destroyed core cloud resources after compromising service principals.

The JadePuffer ransomware operator has escalated its tactics, using agentic AI to orchestrate destructive attacks against Microsoft Azure tenants, according to security research from Sysdig and Microsoft.

In two incidents observed in June, the threat actor tracked as Storm-3168 by Microsoft systematically destroyed core cloud resources. The attackers targeted more than 100 Azure Storage accounts, Key Vaults, Function Apps, Virtual Machines, and App Services. The destructive phase of the attack lasted seven minutes. Some accounts survived due to Azure resource locks and storage account level protections.

The attackers used two compromised service principals belonging to the same tenant. One was used for reconnaissance, the other for destruction and credential collection. Microsoft could not confirm the initial access vector, but noted that credentials for one principal appeared in a public GitHub issue prior to the attacks. Attempts to delete Azure SQL databases failed due to an unsupported API version, and efforts to remove Azure Site Recovery locks also failed.

"The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type," Microsoft said.

JadePuffer first emerged in July, with Sysdig researchers highlighting its use of AI agents to automate the entire attack chain. The group subsequently expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge. The recent activity represents a further evolution into broad cloud resource destruction.

Microsoft recommends that system administrators activate cloud workload protections, monitor for secrets in public repositories, and regularly evaluate the permissions assigned to service principals.

§

Analysis

Why This Matters

  • Marks an evolution where AI agents automate the full kill chain of cloud attacks, shrinking the window for defenders to just minutes.
  • Targeting of backup and recovery locks indicates attackers are systematically eliminating recovery options, strengthening extortion leverage.
  • Exploitation of legitimate service principals highlights a critical blind spot in cloud identity security.

Background

JadePuffer surfaced in mid-2026 as a ransomware operation using AI agents to automate attacks. Sysdig documented its use of an agent called EncForge to target AI models and datasets. The group has now moved beyond data theft to actively destroying cloud infrastructure. The term "agentic AI" refers to autonomous systems that can plan and execute multi-step objectives, in this case the systematic mapping and deletion of cloud resources.

Key Perspectives

Security Researchers (Microsoft, Sysdig): Emphasize the need for proactive defense, including strict access controls for service principals and scanning for exposed credentials. Enterprise Cloud Customers: Are confronted with an attack that exploits their own authorized access and requires automated defensive responses, as manual reaction is too slow. Critics and Skeptics: May argue that the threat is overstated or that the core vulnerabilities (credential leaks, overprivileged accounts) are well known, and the AI element is simply an evolution of automated scripting.

What to Watch

  • Whether other ransomware groups adopt similar agentic AI techniques for cloud resource destruction.
  • Microsoft's implementation of more granular protections against automated resource deletion by compromised principals.
  • Further attacks by Storm-3168 or the JadePuffer group, particularly if they resolve the technical limitations encountered in the June campaign.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.