Skip to content
daily-hour-news·

🛡️Storm-3168: First Agentic Ransomware Wipes Azure Storage

TL;DR

Microsoft documented JADEPUFFER, the first agentic ransomware operation it has seen. Attackers used stolen Azure service principal credentials, found in a public GitHub issue's edit history, to delete cloud resources.

Microsoft documented JADEPUFFER, the first agentic ransomware operation it has seen. Attackers used stolen Azure service principal credentials, found in a public GitHub issue's edit history, to delete cloud resources.

Storm-3168: First Agentic Ransomware Wipes Azure Storage — daily-hour-news

Key Points

1

About 15.5 hours of reconnaissance with 300+ successful read operations

2

Destruction ran in a roughly 7-minute burst, 150+ delete attempts in 35 minutes

3

30+ ListKeys calls harvested storage account access keys

4

Credentials leaked in a public GitHub issue, still visible in edit history

5

Fixes: least-privilege service principals, resource locks, protected backups

Why It Matters

Agents shrink the attacker's time from recon to destruction to minutes. Rotate any secret that ever touched a public repo, even if you edited it out.

Quick Facts

MicrosoftAzureagentic ransomwareJADEPUFFERcybersecurityservice principalscloud security

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,538 builders reading daily.

Also get