The JadePuffer ransomware operator has escalated its tactics, using agentic AI to orchestrate destructive attacks against Microsoft Azure tenants, according to security research from Sysdig and Microsoft.
In two incidents observed in June, the threat actor tracked as Storm-3168 by Microsoft systematically destroyed core cloud resources. The attackers targeted more than 100 Azure Storage accounts, Key Vaults, Function Apps, Virtual Machines, and App Services. The destructive phase of the attack lasted seven minutes. Some accounts survived due to Azure resource locks and storage account level protections.
The attackers used two compromised service principals belonging to the same tenant. One was used for reconnaissance, the other for destruction and credential collection. Microsoft could not confirm the initial access vector, but noted that credentials for one principal appeared in a public GitHub issue prior to the attacks. Attempts to delete Azure SQL databases failed due to an unsupported API version, and efforts to remove Azure Site Recovery locks also failed.
"The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type," Microsoft said.
JadePuffer first emerged in July, with Sysdig researchers highlighting its use of AI agents to automate the entire attack chain. The group subsequently expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge. The recent activity represents a further evolution into broad cloud resource destruction.
Microsoft recommends that system administrators activate cloud workload protections, monitor for secrets in public repositories, and regularly evaluate the permissions assigned to service principals.