JadePuffer AI-Driven Attacks Target Azure Tenants and Delete Cloud Resources
JadePuffer ransomware operators are targeting Microsoft Azure tenants with agent-driven attacks that automate reconnaissance, credential theft, lateral movement, persistence, and the destruction of critical cloud resources.
JadePuffer automates the cloud attack chain
The malware emerged in July, and researchers at cloud security firm Sysdig reported that it uses AI agents to automate the attack chain, including reconnaissance, credential theft, lateral movement, persistence, and data encryption.
Sysdig later said that JadePuffer had expanded its focus to AI assets, training datasets, and vector databases using a tool called EncForge.
Microsoft Security Research observed two JadePuffer attacks in June. The attacks mapped Azure cloud resources, retrieved storage account keys, and deleted Azure Storage accounts.
Storm-3168 targeted more than 100 Azure resources
The destructive phase lasted seven minutes and targeted more than 100 storage accounts, key vaults, function apps, virtual machines, and App Services.
Although the attackers deleted most of the targeted Azure storage accounts, some remained unaffected because of Azure Resource Lock and storage account-level protections.
Microsoft tracks the JadePuffer threat actor as Storm-3168. The company said the group used two compromised service principals—security identities that allow applications, hosted services, and automated tools to authenticate to Azure and access assigned resources.
Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other was used to “perform discovery, sabotage operations, and credential gathering.”
.jpg)
Source: Microsoft
Attackers removed Azure backup protections
The attackers removed backup and recovery protection, including the Azure Site Recovery lock, indicating an attempt to make restoration more difficult.
This activity could support ransomware extortion. However, Microsoft has not reported any financial demands or confirmed data theft in the observed attacks.
According to researchers, attempts to delete an Azure SQL database failed because the attackers used an unsupported API version. An attempt to release the recovery protection lock also failed.
“Targeting Azure SQL databases and storage accounts simultaneously suggests an effort to spread the disruptive impact across a variety of data services, rather than focusing on a single resource type,” Microsoft said.
Approximately 30 minutes after the wipe attempt, Storm-3168 made more than 30 additional requests for storage account keys. Most of those requests were successful.
Exposed service principal credentials may have enabled access
Microsoft could not determine exactly how the attackers gained initial access. However, the company noted that credentials for one service principal had been posted in a public GitHub issue before the attack.
How to protect Azure environments from JadePuffer attacks
Researchers recommend that system administrators take several steps to reduce the risk of similar cloud attacks:
- Activate cloud workload protection.
- Search public repositories for exposed secrets and credentials.
- Review Azure RBAC permissions and apply the principle of least privilege.
- Use Azure Resource Lock and storage account-level protections where appropriate.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



