By Interestana AI Editorial — AI-drafted, human-overseen. How we report
JADEPUFFER Attackers Used Compromised Azure Service Principals

The threat actor identified as JADEPUFFER has been observed executing destructive actions within a Microsoft Azure environment by leveraging compromised service principals. Microsoft, which is tracking this activity under the designation Storm-3168, has characterized these actions as an advancement in the threat actor's operational methods. The observed attack occurred in early June 2026 and spanned approximately 18 hours, during which the attackers focused on deleting resources within the targeted Azure tenant. This tactic represents a significant escalation from JADEPUFFER's previously documented activities, which often involved data exfiltration and espionage. By gaining control of legitimate service principals, which are non-human identities used by applications and services to access Azure resources, JADEPUFFER was able to bypass many standard security controls that are designed to protect user accounts. Service principals are essential for the automation and integration of cloud services, but their compromise can grant attackers extensive privileges. The specific method of compromise for these service principals has not been detailed by Microsoft, but common vectors include credential theft, misconfigurations, or exploitation of vulnerabilities in applications that manage these principals. The destructive nature of this attack, involving the deletion of Azure resources, suggests a motive beyond financial gain or intelligence gathering, potentially aiming to disrupt operations, cause significant damage, or serve as a diversion for other malicious activities. Microsoft's detailed analysis, published in a security advisory, highlights the importance of robust identity and access management within Azure environments. The advisory emphasizes the need for continuous monitoring of service principal activity, strict adherence to the principle of least privilege, and regular auditing of permissions assigned to these identities. Furthermore, it recommends implementing strong authentication mechanisms for service principals and employing tools that can detect anomalous behavior, such as unusual resource deletion patterns or access from unexpected geographic locations. The incident underscores the evolving sophistication of threat actors targeting cloud infrastructure and the critical need for organizations to adapt their security strategies accordingly. The ability of JADEPUFFER to execute such a targeted and destructive campaign within a cloud environment indicates a deep understanding of Azure's architecture and security features. This event serves as a stark reminder for organizations utilizing cloud services to prioritize security best practices, including regular security assessments, employee training on phishing and social engineering tactics, and the deployment of advanced threat detection and response solutions. The duration of the attack, 18 hours, suggests a period of sustained activity, allowing the attackers to systematically identify and delete critical resources. The focus on resource deletion specifically targets the availability of services, a common objective in destructive cyberattacks. Microsoft's tracking of JADEPUFFER as Storm-3168 suggests that this actor is part of a larger, more organized threat landscape, potentially linked to state-sponsored activities or sophisticated criminal enterprises. The evolution of their tradecraft from espionage to destructive operations signifies a broadening of their capabilities and objectives.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.