JADEPUFFER Threat Actors Delete Azure Resources Using Compromised Service Principals
What Happened – The group known as JADEPUFFER (tracked by Microsoft as Storm‑3168) leveraged compromised Azure service‑principal credentials to issue delete commands against Azure Resource Manager APIs. Over an 18‑hour window in early June 2026 the attackers removed virtual machines, storage accounts and other cloud assets across multiple tenant subscriptions.
Why It Matters for Trust & Control Assurance
- The incident is a textbook case of privileged‑access abuse that a continuous control‑assurance program is built to detect, log and remediate.
- Without immutable audit trails of service‑principal activity, organizations lack defensible evidence for auditors and regulators.
- Enforcing just‑in‑time, time‑bound permissions for service principals directly addresses the control objective of “Identity and Access Management” in NIST CSF 2.0.
Who Is Affected – Enterprises and MSPs that run production workloads on Microsoft Azure and rely on service‑principal authentication for automation.
Recommended Actions
- Conduct an inventory of all Azure service principals; retire or disable any that are unused.
- Enforce MFA, certificate‑based auth, or Azure AD Conditional Access for privileged service principals.
- Implement Just‑In‑Time (JIT) or time‑bound access for automation accounts.
- Enable Azure Activity Log alerts for delete operations and retain logs in an immutable store.
- Rotate secrets regularly and store them in a dedicated secret‑management vault.
Technical Notes – The attackers exploited stolen service‑principal credentials (likely harvested from insecure code repositories or leaked secrets). No public CVE is involved; the vector is credential compromise leading to API‑based resource deletion. Source: The Hacker News