Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

JADEPUFFER (Storm-3168) Uses Stolen Azure Service Principals to Enumerate and Delete Storage Accounts

Microsoft reports that the threat group Storm‑3168, also known as JADEPUFFER, compromised two Azure service‑principal identities to conduct rapid reconnaissance, harvest keys, and delete over 100 storage accounts within minutes. The incident highlights the risk of unmanaged non‑human identities in cloud environments and underscores the need for continuous identity monitoring and control assurance.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

JADEPUFFER (Storm‑3168) Leverages Stolen Azure Service Principals to Enumerate and Delete Cloud Storage

What Happened — Microsoft disclosed that the threat group Storm‑3168, also tracked as JADEPUFFER, compromised two Azure service‑principal identities belonging to a single tenant. Using one principal for reconnaissance and the second for rapid destruction, the actors listed VMs, subscriptions and configuration stores, harvested keys, and within 35 minutes attempted >150 destructive operations, successfully deleting more than 100 Azure Storage accounts.

Why It Matters for Trust & Control Assurance

  • Demonstrates how stolen non‑human identities can bypass traditional user‑focused controls, stressing the need for continuous monitoring of service‑principal activity.
  • Highlights a gap in credential‑lifecycle management; without automated evidence of privileged‑identity usage, organizations lack a defensible audit trail.
  • Directly tests the control objective of Identity & Access Management – ensuring that privileged cloud identities are provisioned, monitored, and revoked in line with policy.

Who Is Affected – Cloud‑service providers, SaaS vendors, and any organization running workloads on Microsoft Azure (spanning finance, healthcare, technology, manufacturing, etc.).

Recommended Actions

  • Implement continuous monitoring of service‑principal creation, usage patterns, and anomalous API calls.
  • Enforce least‑privilege policies for non‑human identities and rotate credentials on a defined schedule.
  • Integrate Azure Activity logs into a centralized Trust Center for real‑time evidence collection and audit readiness.

Technical Notes – The actors used the Python requests library (v2.34.2) as their user‑agent, leveraged Azure Resource Manager APIs for enumeration, and performed rapid ListKey and Delete operations against storage accounts. No public CVE is associated; the attack exploits stolen credentials rather than a software flaw. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →