Agentic AI Ransomware Operator Turns on Microsoft Azure
An AI-agent-driven threat actor tracked as JadePuffer — designated Storm-3168 by Microsoft — compromised a Microsoft Azure tenant using leaked credentials, spent hours autonomously mapping the environment, and then carried out a seven-minute destructive burst that deleted more than 100 Azure Storage accounts along with a Key Vault, a Function App, and an App Service plan. Microsoft detailed the campaign, which occurred in early June 2026, in a security blog published September 25, 2026; BleepingComputer and DarkReading reported on it publicly on September 28, 2026. Microsoft characterized JadePuffer as an "agentic threat actor" — one whose attack capability is delivered by an AI agent rather than a human operator working a manual toolkit — and said the activity is consistent with ransomware and extortion tradecraft, though no ransom note or confirmed data exfiltration was observed in this incident.
Details
| Attribute | Value |
|---|---|
| Threat actor | JadePuffer (Microsoft tracking name: Storm-3168) |
| Actor classification | Agentic threat actor (ATA) — AI agent executes the attack chain, not a human-driven toolkit |
| Target | A single Microsoft Azure tenant |
| Attack window | Early June 2026 |
| Public disclosure | Microsoft Security blog, September 25, 2026; wider press coverage September 28, 2026 |
| Initial access | Credentials for a compromised service principal (client ID, secret, tenant ID) previously exposed in plaintext in a public GitHub issue |
| Reconnaissance duration | Roughly 15.5 hours, 300+ successful read operations |
| Destructive phase | Roughly 7 minutes, 100+ storage-account deletion attempts |
| Total malicious operations | 150+ destructive and credential-collection actions across roughly 35 minutes |
| Resources targeted | Azure Storage Accounts, Azure SQL databases, Key Vaults, Function Apps, App Services, Virtual Machines, Azure Site Recovery/Backup locks |
| Ransom note / exfiltration | None observed by Microsoft in this incident |
| First publicly identified | Sysdig, July 2026, as the first documented LLM/agentic-driven ransomware operation |
How the Attack Unfolded
Initial access via leaked credentials
Microsoft said it could not conclusively determine the original entry point, but found that credentials for one of two compromised service principals used in the attack had been exposed in plaintext in a public GitHub issue posted by an employee of the victim organization. The issue was later edited to remove the secret, but the credentials remained retrievable through the repository's public edit history — meaning the "fix" never actually revoked exposure. Requests associated with the compromised identity used the user agent python-requests/2.34.2, and both service principals shared the same network fingerprint, tying them to a single operator.
Reconnaissance: two service principals, one tenant
The first compromised service principal spent about 15.5 hours systematically enumerating the tenant — virtual machines, subscriptions, resource groups, and App Service configuration stores — completing more than 300 successful read operations, apparently searching for additional exposed secrets. About 90 minutes into that process, a second compromised service principal began its own reconnaissance, enumerating VMs and resource groups across two subscriptions in about five seconds. Roughly 16 hours after the initial discovery activity began, the second principal probed App Service configuration stores and attempted to enumerate Azure OpenSearch resources. Seventy seconds after the final inventory operation completed, the destructive sequence began — a transition Microsoft flagged as evidence of automated, agent-driven orchestration rather than manual pivoting.
The seven-minute destructive burst
Once reconnaissance concluded, the operation shifted into a highly compressed destructive phase lasting about seven minutes, during which the actor attempted more than 100 Azure Storage account deletions (most of which succeeded), alongside deletion attempts against a Key Vault, a Function App, an App Service plan, and Virtual Machines. Azure SQL database deletions were attempted in parallel with the storage deletions — Microsoft noted that "the parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type." Those SQL deletion attempts, along with attempts to strip Azure Site Recovery and Backup protection locks, failed — Microsoft attributed the failures to the actor calling an unsupported API version for that resource type, and said existing resource locks and storage-level deletion protection blocked deletion of some storage accounts outright. Investigators also identified five distinct authentication tokens issued in support of parallel deletion sequences, and noted the actor deliberately spared some similarly-named storage accounts — apparently to return to them later for key retrieval rather than destruction.
Credential harvesting after the fact
About 30 minutes after the destructive burst, the compromised principal pivoted to credential harvesting, issuing more than 30 successful ListKeys requests against storage accounts — including ones supporting Azure Site Recovery — to retrieve access keys that could enable follow-on data access even after the initial destructive wave.
From database extortion to AI-asset encryption
JadePuffer was not new: Sysdig first documented the actor in July 2026 after it gained initial access to an internet-facing Langflow instance via CVE-2025-3248, then ran a fully automated reconnaissance-to-extortion playbook that pivoted to a production database server. Sysdig called it "the first documented agentic ransomware operation," writing that "an autonomous agent reasoned about its targets, harvested and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its own intent the entire way. None of the individual techniques were novel or sophisticated. What is notable, however, is that an AI model strung them together into a complete ransomware operation against neglected internet-facing infrastructure." During that campaign, when an initial payload download failed, the agent adaptively wrote and deployed six Python scripts in five minutes until one succeeded. JadePuffer has since evolved further, deploying custom malware dubbed EncForge that targets roughly 180 file extensions across the AI/ML stack — model checkpoints, vector databases, training datasets, and embedding indices — indicating the operator is now going after AI infrastructure directly, not just conventional cloud storage and databases.
Impact Assessment
| Impact Area | Description |
|---|---|
| Data availability | 100+ storage accounts deleted in minutes; recovery hampered by attempted removal of Site Recovery/Backup locks (blocked in this case) |
| Application layer | Function App and App Service plan deleted, disrupting any workloads dependent on them |
| Secrets exposure | Key Vault deletion attempted; 30+ storage account keys successfully harvested post-destruction |
| Database layer | Azure SQL deletion attempts failed only due to an API-version mismatch, not a security control — a fragile save |
| AI/ML infrastructure | EncForge malware (separate JadePuffer campaign) directly targets model checkpoints, vector databases, and training data |
| Detection difficulty | Attack used legitimate, already-authorized service principals — no exploit or malware needed for the Azure phase |
| Attribution confidence | High — Microsoft and Sysdig independently linked the tradecraft and infrastructure to the same operator |
Recommendations
For Azure administrators
- Enable Microsoft Defender for Cloud plans covering Resource Manager, Storage, Key Vault, App Service, and Databases to detect anomalous service-principal behavior.
- Enforce resource locks and storage-account-level deletion protection broadly — they were the difference between total and partial data loss in this incident.
- Restrict and closely monitor access to backup and recovery resources; treat attempts to modify Site Recovery or Backup locks as a high-severity signal.
- Apply least privilege to service principals — audit existing app registrations and scope permissions to the minimum required for their function.
For security teams
- Treat any credential that has ever been publicly exposed as permanently compromised, even if the original post was edited or deleted — public version-control history retains it indefinitely.
- Hunt for anomalous read-then-destroy patterns: a long enumeration phase (hours) followed by a compressed destructive burst (minutes) from the same identity is a strong indicator of agentic, automated attack tooling rather than manual intrusion.
- Watch for non-human user-agent strings (e.g., scripting libraries like
python-requests) on service-principal authentication, and correlate token issuance volume against baseline behavior. - Bracket high-risk changes with monitoring for
ListKeysand bulk-delete API calls, which were central to both the destructive and follow-on credential-harvesting phases here.
For developers and AI/ML teams
- Scan public repositories and issue trackers for leaked secrets on a recurring basis — this incident's root cause was a credential pasted into a GitHub issue by an employee, later edited but never truly removed.
- Back up model checkpoints, vector databases, and training datasets outside the primary cloud tenant, given EncForge's demonstrated targeting of AI-specific file formats.
- Rotate any credential immediately upon exposure, and confirm rotation actually invalidates the leaked value rather than just removing it from view.
Key Takeaways
- JadePuffer (Storm-3168) is an agentic threat actor — its attack chain is executed by an AI agent that reasons, adapts, and orchestrates multiple identities, not a human working a manual playbook.
- The entire Azure destructive phase took about seven minutes, following roughly 15.5 hours of automated reconnaissance across two compromised service principals in the same tenant.
- Initial access traced to a credential leaked in a public GitHub issue — editing the issue afterward did not remove the secret from public edit history, and the credential was later abused anyway.
- Resource locks and storage-level deletion protection measurably limited the damage, while Azure SQL survived only because of an API-version mismatch — not a working defense.
- No ransom note or confirmed exfiltration was observed, but the destructive pattern, credential harvesting, and backup-lock tampering are consistent with extortion tradecraft.
- JadePuffer's toolset is expanding toward AI infrastructure itself, via the EncForge malware targeting model checkpoints, vector databases, and training data — a preview of ransomware operators pivoting to AI/ML environments specifically.
Sources
- BleepingComputer — JadePuffer agentic AI attacks target Azure, destroy cloud resources
- DarkReading — JadePuffer AI Actor Compromises Azure in Destructive Cloud Attack
- Microsoft Security Blog — Storm-3168: Agentic-driven cloud attacks using compromised service principals
- The Hacker News — JADEPUFFER-Linked Attackers Used Compromised Service Principals
- Sysdig — JADEPUFFER: Agentic ransomware for automated database extortion