JADEPUFFER (Storm‑3168) Leverages Stolen Azure Service Principals to Enumerate and Delete Cloud Storage
What Happened — Microsoft disclosed that the threat group Storm‑3168, also tracked as JADEPUFFER, compromised two Azure service‑principal identities belonging to a single tenant. Using one principal for reconnaissance and the second for rapid destruction, the actors listed VMs, subscriptions and configuration stores, harvested keys, and within 35 minutes attempted >150 destructive operations, successfully deleting more than 100 Azure Storage accounts.
Why It Matters for Trust & Control Assurance
- Demonstrates how stolen non‑human identities can bypass traditional user‑focused controls, stressing the need for continuous monitoring of service‑principal activity.
- Highlights a gap in credential‑lifecycle management; without automated evidence of privileged‑identity usage, organizations lack a defensible audit trail.
- Directly tests the control objective of Identity & Access Management – ensuring that privileged cloud identities are provisioned, monitored, and revoked in line with policy.
Who Is Affected – Cloud‑service providers, SaaS vendors, and any organization running workloads on Microsoft Azure (spanning finance, healthcare, technology, manufacturing, etc.).
Recommended Actions
- Implement continuous monitoring of service‑principal creation, usage patterns, and anomalous API calls.
- Enforce least‑privilege policies for non‑human identities and rotate credentials on a defined schedule.
- Integrate Azure Activity logs into a centralized Trust Center for real‑time evidence collection and audit readiness.
Technical Notes – The actors used the Python requests library (v2.34.2) as their user‑agent, leveraged Azure Resource Manager APIs for enumeration, and performed rapid ListKey and Delete operations against storage accounts. No public CVE is associated; the attack exploits stolen credentials rather than a software flaw. Source: SecurityAffairs