Microsoft has identified a destructive campaign targeting Azure, known as Storm-3168 or JADEPUFFER. This campaign involved compromised service principals that conducted reconnaissance, deleted cloud resources, disrupted recovery processes, and collected credentials. The operation swiftly transitioned from discovery to destruction, with the attacker initiating a destructive sequence shortly after an unsuccessful ListKey request against an nonexistent storage account.

This sequence lasted approximately seven minutes. The actor deleted Azure Key Vault, Function App, and App Service plans, as well as an Azure SQL database, but failed to remove them due to an unsupported API version. Resource locks and storage account-level deletion protection were effective in preventing some deletion attempts, highlighting the significance of recovery controls that remain effective even when compromised identities have extensive permissions.

The campaign targeted storage, databases, application services, secrets, and recovery mechanisms, consistent with a ransomware or extortion objective, although Microsoft did not identify a ransom note or confirm successful data exfiltration. It observed five tokens for the service principal responsible for deletion and credential collection, with four used for destructive activity and a fifth used for storage enumeration and key retrieval. Defenders must audit service-principal permissions, rotate exposed credentials, enforce least privilege, protect backup resources with independent locks, and monitor for suspicious Azure Resource Manager operations, unusual key-vault access, and anomalous storage-key retrieval.

Explore for your team.