🛡️Storm-3168: First Agentic Ransomware Wipes Azure Storage
TL;DR
Microsoft documented JADEPUFFER, the first agentic ransomware operation it has seen. Attackers used stolen Azure service principal credentials, found in a public GitHub issue's edit history, to delete cloud resources.
Microsoft documented JADEPUFFER, the first agentic ransomware operation it has seen. Attackers used stolen Azure service principal credentials, found in a public GitHub issue's edit history, to delete cloud resources.

Key Points
About 15.5 hours of reconnaissance with 300+ successful read operations
Destruction ran in a roughly 7-minute burst, 150+ delete attempts in 35 minutes
30+ ListKeys calls harvested storage account access keys
Credentials leaked in a public GitHub issue, still visible in edit history
Fixes: least-privilege service principals, resource locks, protected backups
Why It Matters
Agents shrink the attacker's time from recon to destruction to minutes. Rotate any secret that ever touched a public repo, even if you edited it out.
Quick Facts
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,538 builders reading daily.