Storm-3168: Rapid Azure Resource Deletion Campaign Targeting Microsoft Azure Subscriptions
Threat actor JADEPUFFER (Storm-3168) conducted a highly automated, destructive campaign against Microsoft Azure tenants using compromised service principals. Initial access was achieved through service principal secrets exposed in public GitHub issue histories. Following a 15-hour reconnaissance phase involving ~300 read-only API calls, the actor executed a seven-minute burst of over 150 destructive operations. This included deleting >100 storage accounts, Azure Key Vaults, SQL databases, and removing Azure Site Recovery and backup protection locks. Post-destruction, the actor attempted credential harvesting via storageAccount/listKeys calls. The attack pattern—combining rapid resource destruction with recovery-impairment tactics—suggests an extortion-focused methodology designed to pressure victims through immediate operational paralysis.
- Attack Vector & Initial Access
- Exploitation of compromised Azure service principals via leaked client secrets.
- Credentials were recovered from plaintext entries within public GitHub issue edit histories.
-
Attackers leveraged valid identities (T1078) to bypass traditional perimeter defenses and perform discovery.
-
Reconnaissance & Automated Discovery
- First principal performed ~15 hours of stealthy reconnaissance via ~300 successful GET requests.
- Enumerated subscriptions, resource groups, virtual machines, and other critical Azure assets.
-
A second principal performed rapid, multi-subscription discovery within seconds, indicating high automation.
-
Destructive Payload & Impact
- Executed a seven-minute burst of >150 destructive actions (T1485).
- Deleted >100 storage accounts, Key Vaults, Function Apps, App Service plans, and SQL databases.
-
Systematically removed Azure Site Recovery and backup protection locks to prevent rapid resource restoration.
-
Post-Exploitation & Credential Harvesting
- Performed >30
storageAccount/listKeyscalls approximately 30 minutes after the destruction wave. - Targeted storage account access keys to facilitate potential data exfiltration or secondary extortion.
-
The sequence—reconnaissance, destruction, and subsequent harvesting—aligns with advanced extortion-driven tactics.
-
Detection & Mitigation Strategies
- Implement real-time Azure Activity Log alerts for bulk
DELETEandlistKeysoperations. - Enforce least-privilege principles for service principals and mandate frequent secret rotation.
- Utilize Azure Policy to enforce immutable backup storage and prevent deletion of critical resource locks.
- Conduct periodic credential exposure scans to identify secrets leaked in public repositories or version histories.
Related posts
- Cybersecurity News — Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack
- techjacksolutions.com — Agentic Cloud Destruction: Storm-3168 Executes Automated Azure Wipeout in Seven Minutes Using Compromised Service Principals
- Microsoft Security Blog — Storm-3168: Agentic-driven cloud attacks using compromised service principals
- thehackernews.com — JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
- csoonline.com — Autonomous agents attack Azure using compromised identities, destroying resources
- Aviatrix
- Insight
- Daily
- Secarma