Fast Facts
- JADEPUFFER exploited compromised service principals and vulnerabilities like CVE-2025-3248 to gain persistent access and orchestrate destructive Azure resource deletions, including storage accounts and databases.
- The attack involved AI-driven automation, leveraging large language models to coordinate credential harvesting, lateral movement, and rapid execution of over 150 destructive operations within minutes.
- Despite protections, the threat successfully targeted critical Azure assets, emphasizing risks of exposure through public credentials and the importance of independent safeguards against resource deletion.
Threat, Techniques, and Targets
The threat actor, known as JADEPUFFER, used compromised service principals to carry out destructive actions in Azure. Microsoft tracks this activity under the name Storm-3168. The attack took place over approximately 18 hours in early June 2026. The attackers exploited a known vulnerability in Langflow (CVE-2025-3248) to gain access. They harvested credentials and moved deeper into the network. They targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, and App Services. The actors used two different compromised service principals. One was for reconnaissance and discovery. The other was for destructive operations and stealing credentials. The attackers also used AI technology to run end-to-end ransomware operations. They encrypted service configuration files and dropped database tables. They attempted to delete over 100 storage accounts and other resources. The activity included over 300 read operations and more than 150 destructive actions. The second service principal also searched for exposed credentials by examining App Service configurations.
Impact, Implications, and Guidance
Most targeted Azure Storage accounts were successfully deleted. Some resources, like resource locks, prevented the deletion. These safeguards proved valuable, even with broad permissions. The attackers aimed to impair the victim’s recovery ability by deleting resources and backups. Although some delete attempts failed, the attack caused significant disruption. It is not clear how the service principal was compromised. Microsoft observed that sensitive credentials were previously exposed in a public GitHub issue. The attack was likely automated and coordinated across multiple resources. No ransom note or data exfiltration was seen. The activity shows a shift toward AI-driven attacks, which can now move faster and better coordinate complex operations. Microsoft advises organizations to strengthen security measures. Remediation guidance should be obtained from the relevant vendor or authority, as specific steps are not provided here.
Stay Ahead with the Latest Tech Trends
Explore the future of technology with our detailed insights on Artificial Intelligence.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
