Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unraveling the Shadows of Storm-3168: A Complex Ransomware Operation Linked to JADEPUFFER




Unraveling the Shadows of Storm-3168: A Complex Ransomware Operation Linked to JADEPUFFER

In a recent report, Microsoft uncovered a sophisticated ransomware operation linked to JADEPUFFER, highlighting the ever-evolving threat landscape of cloud-based attacks. The operation, known as Storm-3168, showcases the group's ability to move quickly and strike with precision, leveraging stolen service principals to execute a complex series of attacks on Microsoft Azure. This article delves into the details of the attack, exploring the tactics, techniques, and procedures (TTPs) used by the attackers and providing insights into the importance of cloud security awareness and proactive measures to prevent similar attacks.

  • Storm-3168, a sophisticated ransomware operation linked to JADEPUFFER, was uncovered by Microsoft.
  • The attack began with reconnaissance, quickly enumerating virtual machines, subscriptions, and resource groups across two subscriptions.
  • The attackers used stolen service principals, compromised by an employee, to carry out destructive operations.
  • The attack highlighted the importance of securing sensitive credentials and keeping secrets out of code.
  • Microsoft advises defenders to treat exposed credentials as compromised and take immediate action to revoke or rotate them.
  • The discovery serves as a reminder of the complex threat landscape of cloud-based attacks.



  • Storm-3168, a sophisticated ransomware operation linked to the notorious actor JADEPUFFER, has been uncovered by Microsoft, highlighting the ever-evolving threat landscape of cloud-based attacks. The operation, which began in early June 2026, showcases the group's ability to move quickly and strike with precision, leveraging stolen service principals to execute a complex series of attacks on Microsoft Azure.

    The attack began with the reconnaissance phase, where a compromised service principal, identified as the "second identity," quickly enumerated virtual machines, subscriptions, and resource groups across two subscriptions in a mere five seconds. This speed and efficiency were indicative of the group's use of scripted execution, with the two identities working together in tandem to execute their tasks. The timing and division of work between the two identities, as well as overlapping token streams, pointed to a highly automated operation.

    As the attack progressed, the "second identity" carried out destructive operations, including deleting over 100 storage accounts, a Key Vault, a Function App, and an App Service plan. The attackers also targeted backup and recovery systems, attempting to remove Azure Site Recovery locks and Azure Backup protection locks. In some cases, the attackers were unsuccessful due to simple technical errors, such as using an unsupported API version for certain resource types.

    The attackers' use of stolen service principals, which were compromised by an employee of the impacted organization, highlighted the importance of properly securing sensitive credentials. The report noted that the client ID, client secret, and tenant ID had been posted in plaintext in a public GitHub issue, making them easily accessible to malicious actors.

    Microsoft's response to the attack emphasized the need for cloud security awareness, advising defenders to treat any exposed credential as compromised and to take immediate action to revoke or rotate it. The report also highlighted the importance of keeping secrets out of code, config files, repositories, and issues, as well as restricting access to backup and recovery resources.

    The discovery of Storm-3168 and its link to JADEPUFFER serves as a reminder of the complex and ever-evolving threat landscape of cloud-based attacks. As organizations continue to move their operations to the cloud, it is essential that they prioritize cloud security and take proactive measures to prevent similar attacks from occurring.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unraveling-the-Shadows-of-Storm-3168-A-Complex-Ransomware-Operation-Linked-to-JADEPUFFER-ehn.shtml

  • https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html


  • Published: Mon Sep 28 07:18:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us