The JadePuffer cybercrime operation has been caught wrecking Azure infrastructure using stolen application identities, in a destructive burst that lasted just seven minutes.
According to BleepingComputer, Microsoft linked the activity to the outfit it tracks as Storm-3168, previously associated with AI-driven ransomware. Researchers examined activity from June involving two compromised service principals, the identities applications use to access cloud resources.
One mapped the environment while the other handled discovery, destruction and credential collection. Apparently, even digital vandalism now comes with a division of labour. More than 100 Azure storage deletion attempts followed, most of which succeeded. Some resources survived because deletion protections blocked the requests.
Attempts to wipe SQL databases failed because the attacker used an unsupported API version. For once, a compatibility problem did something useful. The attacker then returned to collect storage access keys, potentially creating further opportunities to reach sensitive data.
Microsoft’s underlying research adds that credentials for one compromised identity had appeared in a public GitHub issue. Someone edited the issue to remove the secret, but it remained visible in the edit history. Microsoft could not confirm whether those exposed credentials provided the initial entry point.
Deleting the visible password while leaving it valid is unlikely to trouble anyone who can click a history button. The AI label needs some care. Microsoft found strong evidence of automated or scripted execution, while JadePuffer’s connection to agentic ransomware comes from earlier research.
That does not establish that an AI model directed every action in this Azure intrusion. Microsoft said attempts to remove backup and recovery protection locks failed, a useful correction to suggestions that the attackers successfully stripped those safeguards.
The researchers described the behaviour as consistent with operations supporting extortion, but stated: “However, we did not observe a ransom note or confirm successful data exfiltration in the activity described here.”







