VMTech
Discuss a project →

Compromised Azure service principals enabled JADEPUFFER deletions

Compromised Azure service principals enabled JADEPUFFER deletions

Microsoft has observed the threat actor JADEPUFFER, which it tracks as Storm-3168, using compromised Azure service principals to carry out destructive operations in a customer environment. The intrusion occurred in early June 2026 over about 18 hours and included attempts to delete Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, virtual machines and App Services.

The incident shows how a non-human cloud identity with broad permissions can become a destructive access path. Microsoft linked two compromised service principals to the same tenant: one was used for reconnaissance and resource discovery, while the other carried out destructive activity and credential collection.

Long reconnaissance preceded a short deletion sequence

For close to 16 hours, the first service principal enumerated Azure virtual machines, subscriptions, resource groups and resources, generating more than 300 read operations. About 90 minutes later, the second principal also queried virtual machines and resource groups across two subscriptions within five seconds.

After 16 hours, that second identity successfully enumerated Azure App Service configuration stores, an action Microsoft said was likely intended to find exposed credentials. It then performed more than 150 destructive or credential-collection-related operations in 35 minutes.

The destructive sequence itself lasted about seven minutes and included more than 100 attempts to delete storage accounts. The actor also targeted an Azure Key Vault, Function App, App Service plan and multiple Azure SQL databases. Every database deletion attempt failed because an unsupported API version was used for the Azure SQL database resource type.

Independent safeguards limited part of the damage

Microsoft said most of the targeted Azure Storage accounts were successfully deleted. However, Azure resource locks and storage-account-level deletion protection prevented deletion of some accounts. Those controls remained effective despite the compromised identity having broad administrative permissions.

The service principal's client ID, client secret and tenant ID had previously been exposed in plaintext in a public GitHub issue by an employee of the affected organization. Although the secret was removed, it was still available in the issue's public edit history. Microsoft said it could not determine how the service principal was compromised, but the exposed values were observed before the incident.

Ransomware-aligned activity without a ransom note

Microsoft assessed the operation as ransomware-aligned because it deleted numerous Azure resources and targeted backup and recovery-related resources, indicating an attempt to impair recovery. It found no ransom note or successful data exfiltration connected to the intrusion.

JADEPUFFER was first documented by Sysdig in activity exploiting Langflow vulnerability CVE-2025-3248. Sysdig described that operation as an end-to-end ransomware campaign assisted by a large language model. Microsoft also detected repeated probing from Storm-3168-linked infrastructure against Azure App Services belonging to several customers, and said the division of work between service principals and the timing of actions suggested automation or scripting.

For businesses, the practical priority is to treat service-principal secrets as high-impact credentials: remove exposed values from public history where possible, rotate them promptly, restrict permissions, and maintain deletion protections and resource locks that do not rely solely on a privileged identity.

#azuresecurity#cloudsecurity#identitysecurity#ransomware
Open analytics
On the site 2 views
min read 4 28.09.2026
Instagram

Compromised Azure service principals enabled JADEPUFFER deletions

Open the post on Instagram ↗