How JADEPUFFER (tracked as Storm-3168) used compromised service principals
Microsoft's analysis describes an attack in early June 2026 in which the threat actor known as JADEPUFFER — tracked by Microsoft under the name Storm-3168 — carried out destructive operations inside a single Azure tenant by leveraging two compromised service principals. According to Microsoft, one service principal was used primarily for reconnaissance and resource discovery while a second was used for destructive actions and credential collection. The division of labor, plus timing between operations, led Microsoft to conclude the activity was likely automated or scripted.
Timeline and scale of the intrusion
The intrusion unfolded over roughly 18 hours. Enumeration activity went on for nearly 16 hours and targeted Azure Virtual Machines, subscriptions, resource groups, and other resources; Microsoft observed more than 300 read operations during that phase. About 90 minutes into the second service principal's activity, it enumerated virtual machines and resource groups across two subscriptions within a five-second window. After 16 hours, that same principal enumerated Azure App Service configuration stores, likely searching for exposed credentials, then performed more than 150 destructive or credential-collection operations in a 35-minute span.
Microsoft says the final destructive burst lasted roughly seven minutes and included over 100 attempts to delete storage accounts. The actor also targeted an Azure Key Vault, a Function App, an App Service plan, and multiple Azure SQL databases; the SQL deletion attempts failed because the attacker used an unsupported API version for that resource type. No ransom note or confirmed data exfiltration was observed in connection with the intrusion.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTools and techniques observed: Langflow CVE-2025-3248, ENCFORGE, and agentic behavior
Microsoft and prior reporting by Sysdig place this activity within a broader pattern that includes AI-assisted operations. Sysdig first documented JADEPUFFER as an operation that used a large language model (LLM) end-to-end, exploiting Langflow via CVE-2025-3248 to gain initial access, harvest credentials, move laterally, and encrypt configuration files. After that incident, the same Langflow instance was later targeted with a compiled Go-based ransomware strain codenamed ENCFORGE.
ENCFORGE is built specifically for AI infrastructure and was observed scanning for nearly 180 file extensions, including model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files such as Keychain stores and Xcode project files. Sysdig characterized the earlier operation as an autonomous agent that "reasoned about its targets, harvested and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its own intent the entire way." Microsoft called the Azure deletions an evolution of that tradecraft.
Defensive measures that limited damage
Microsoft reported that most targeted Azure Storage accounts were successfully deleted, but independent safeguards prevented loss in some cases. Specifically, Azure resource locks and storage account–level deletion protection blocked deletion attempts for a subset of storage accounts — an outcome Microsoft cited as evidence of the value of independent protections that remain effective even when a compromised identity has broad permissions.
Microsoft also highlighted that the SQL deletions failed because the attacker used an unsupported API version, which unintentionally limited impact on those resources. Nevertheless, Microsoft assessed the end goal of the activity as ransomware-aligned because the actor deleted backup and recovery-related resources in addition to primary assets, indicating an intent to impair recovery even without a successful ransom demand or observed exfiltration.
What this means for technologists, enterprise security teams, and developers
- Technologists and security teams: The incident underscores how a single exposed credential can enable prolonged, automated reconnaissance followed by rapid destructive actions. The attack timeline shows that defenders must monitor service-principal activity, audit resource locks and deletion protections, and use rapid detection to disrupt automated sequences.
- Enterprise security and recovery planners: Because the actor targeted backup and recovery resources, organizations should validate that independent safeguards like resource locks and storage-level protections are in place and cannot be removed by identities that should not have such authority.
- Developers and employees who manage code and issues: Microsoft observed that the client ID, client secret, and tenant ID had been exposed in plaintext in a public GitHub issue by an employee of the impacted organization; although the secret was removed, it remained available in the public edit history. That finding points to the concrete risk of credential leakage through public issue trackers and the need to treat edit histories as a potential disclosure vector.
"This activity highlights a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale," Microsoft said, and added that "as these capabilities evolve, defenders must similarly use AI to investigate and respond across large environments."
The immediate record from Microsoft and Sysdig ties a familiar set of techniques — credential harvesting, scripted enumeration, and resource deletion — to a new pattern of orchestration that leverages automation and AI reasoning. The clearest open question is operational: will organizations harden service-principal hygiene, lock controls, and public-issue practices quickly enough to blunt further automated, AI-orchestrated destructive campaigns?
Source: https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html



