← Back to Daily Briefing (#Azure)

Storm-3168: Rapid Azure Resource Deletion Campaign Targeting Microsoft Azure Subscriptions

Published October 2, 2026

Threat actor JADEPUFFER (Storm-3168) conducted a highly automated, destructive campaign against Microsoft Azure tenants using compromised service principals. Initial access was achieved through service principal secrets exposed in public GitHub issue histories. Following a 15-hour reconnaissance phase involving ~300 read-only API calls, the actor executed a seven-minute burst of over 150 destructive operations. This included deleting >100 storage accounts, Azure Key Vaults, SQL databases, and removing Azure Site Recovery and backup protection locks. Post-destruction, the actor attempted credential harvesting via storageAccount/listKeys calls. The attack pattern—combining rapid resource destruction with recovery-impairment tactics—suggests an extortion-focused methodology designed to pressure victims through immediate operational paralysis.

  • Attack Vector & Initial Access
  • Exploitation of compromised Azure service principals via leaked client secrets.
  • Credentials were recovered from plaintext entries within public GitHub issue edit histories.
  • Attackers leveraged valid identities (T1078) to bypass traditional perimeter defenses and perform discovery.

  • Reconnaissance & Automated Discovery

  • First principal performed ~15 hours of stealthy reconnaissance via ~300 successful GET requests.
  • Enumerated subscriptions, resource groups, virtual machines, and other critical Azure assets.
  • A second principal performed rapid, multi-subscription discovery within seconds, indicating high automation.

  • Destructive Payload & Impact

  • Executed a seven-minute burst of >150 destructive actions (T1485).
  • Deleted >100 storage accounts, Key Vaults, Function Apps, App Service plans, and SQL databases.
  • Systematically removed Azure Site Recovery and backup protection locks to prevent rapid resource restoration.

  • Post-Exploitation & Credential Harvesting

  • Performed >30 storageAccount/listKeys calls approximately 30 minutes after the destruction wave.
  • Targeted storage account access keys to facilitate potential data exfiltration or secondary extortion.
  • The sequence—reconnaissance, destruction, and subsequent harvesting—aligns with advanced extortion-driven tactics.

  • Detection & Mitigation Strategies

  • Implement real-time Azure Activity Log alerts for bulk DELETE and listKeys operations.
  • Enforce least-privilege principles for service principals and mandate frequent secret rotation.
  • Utilize Azure Policy to enforce immutable backup storage and prevent deletion of critical resource locks.
  • Conduct periodic credential exposure scans to identify secrets leaked in public repositories or version histories.

Related posts

  1. Cybersecurity News — Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack
  2. techjacksolutions.com — Agentic Cloud Destruction: Storm-3168 Executes Automated Azure Wipeout in Seven Minutes Using Compromised Service Principals
  3. Microsoft Security Blog — Storm-3168: Agentic-driven cloud attacks using compromised service principals
  4. thehackernews.com — JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
  5. csoonline.com — Autonomous agents attack Azure using compromised identities, destroying resources
  6. Aviatrix
  7. Insight
  8. Daily
  9. Secarma

LINK COPIED TO CLIPBOARD