Skip to content
theregister·

🚨Storm-3168 Uses Stolen Azure Ids for Destructive Attacks

Stolen Azure identities lead to widespread destruction

TL;DR

Storm-3168, behind JadePuffer, used stolen Azure identities to launch destructive attacks, deleting over 100 Azure Storage accounts and an Azure Key Vault in just 7 minutes. This highlights the critical need for robust identity and access management in the cloud.

Storm-3168, the cyber criminal behind the first agentic ransomware infection, JadePuffer, has used stolen Azure identities to conduct destructive attacks on cloud storage and resources. The attacks lasted around 18 hours, with destructive activity taking just 7 minutes. Over 100 Azure Storage accounts were deleted, along with an Azure Key Vault and other resources. This highlights the critical need for robust identity and access management in the cloud. The compromised service principal completed over 300 read operations in just five seconds, demonstrating the speed and scale of the attack. The attacker targeted backup and recovery resources, indicating a sophisticated approach to maximizing damage.

Storm-3168 Uses Stolen Azure Ids for Destructive Attacks — theregister

Key Points

1

Storm-3168 conducted destructive attacks using stolen Azure identities, deleting over 100 Azure Storage accounts in 7 minutes.

2

The attacker completed over 300 read operations in just five seconds, showcasing the speed of the attack.

3

Azure Key Vault, Function App, and App service plan were deleted from the same resource group.

4

The attack included attempting to delete multiple Azure SQL databases in parallel with storage account deletions.

5

The compromised service principal made an inventory request for Azure Storage Accounts and sent over 30 ListKeys requests.

Why It Matters

If you manage Azure resources, this attack highlights the critical need for robust identity and access management. The attacker deleted over 100 Azure Storage accounts and an Azure Key Vault in just 7 minutes, demonstrating the potential for rapid, extensive damage. The attack also targeted backup and recovery resources, underscoring the importance of securing these critical components.

azurestorm-3168ransomwarecloud-securityiam

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Also get