Storm-3168 Cloud Attack Uses Compromised Service Principals for Destructive Operations
A threat actor tracked as Storm-3168 has been linked to malicious cloud activity involving compromised service principals and credential collection. The attack, dubbed JADEPUFFER by Sysdig in July 2026, is believed to be the first documented agentic ransomware operation.
The investigation revealed that two compromised service principals belonging to the same tenant performed reconnaissance and resource discovery, followed by destructive operations and credential collection. The threat actor targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services.
Experts warn that organizations can reduce exposure by protecting workload identities and secrets, enforcing least privilege, safeguarding recovery resources, and enabling relevant Microsoft Defender for Cloud protections. The incident highlights a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale.