Microsoft says Jadepuffer, an autonomous agentic AI attacker first reported in July, is now targeting Azure resources; exposed credentials may have provided a way in.
Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft.
The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration,” Microsoft said in a blog post about Storm-3168, also known as Jadepuffer. Service principals are unique machine identities given to applications running within Azure.
“The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services,” Microsoft said in the blog post, “Storm-3168: Agentic-driven cloud attacks using compromised service principals.”
The campaign was first reported in July by Sysdig, which described Jadepuffer as an AI-driven operation capable of executing attack steps autonomously, including exploitation, credential access and destructive activity.
Two identities, split roles
Microsoft said it observed two compromised service principals in the same tenant, with one performing reconnaissance and the other carrying out discovery, destructive actions and credential collection.
One of the identities spent more than 15 hours enumerating virtual machines, subscriptions, resource groups and other resources, making more than 300 successful read operations, the company said.
A second service principal enumerated resources across multiple subscriptions within seconds and later conducted additional discovery, Microsoft said.
The timing and division of activity “strongly indicates automated or scripted execution,” the company said.
Nick Tausek, lead security automation architect at Swimlane, said the pattern aligns with earlier observations of the campaign’s behavior.
“Jadepuffer’s earlier database attack showed an AI agent working through an extortion playbook and adjusting when steps failed,” Tausek said. “Microsoft now traces the group into Azure, where compromised service principals mapped resources before a seven-minute burst of destruction.”
Destructive sequence lasted minutes
After the two agents had completed their reconnaissance they began to create mayhem, conducting more than 150 destructive or credential-related operations over about 35 minutes.
The main destructive sequence lasted about seven minutes and included more than 100 attempts to delete storage accounts, most of which were successful, the blog post said.
The attackers also deleted an Azure Key Vault, Function App and App Service plan tied to the same resource group, Microsoft said.
Attempts were also made to delete Azure SQL databases and backup-related protections, including Azure Site Recovery locks and backup protection locks, the company said.
Tausek said the speed and coordination of the activity could challenge traditional response models.
“At that speed, an AI SOC needs to connect identity activity with cloud changes before the damage spreads,” he said.
Credential access followed destruction
About 30 minutes after the destructive activity, the same service principal requested storage account access keys, making more than 30 successful ListKeys requests, Microsoft said.
The requests included storage accounts associated with recovery services, the blog post said.
Microsoft said the combination of resource deletion, attempts to interfere with recovery mechanisms and credential collection is “consistent with tactics that can support ransomware and extortion operations.”
The company said it did not observe a ransom note or confirm data exfiltration in the activity.
Ross Filipek, CISO at Corsica Technologies, said the sequence of destruction followed by credential access raises additional response challenges.
“The recovery question here goes beyond rebuilding what was deleted,” Filipek said. “The attackers later requested storage account keys, potentially giving them another route to data.”
“Responders need to establish which identities and keys were touched, then review their use before trusting restored services,” he said.
Possible credential exposure
Microsoft said it could not confirm the initial access vector but found that credentials associated with a compromised service principal had previously been exposed in plaintext in a public GitHub issue.
The secret was later removed but remained accessible in the edit history, the company said.
“Publicly exposed credentials remain usable until revoked or rotated; removing the original disclosure alone does not remediate the exposure,” Microsoft said.
Filipek said the finding highlights a common risk in cloud environments.
“A cloud credential remained visible in a GitHub issue’s edit history after someone removed it from the post,” he said. “For an IT team, it’s a useful warning about how a routine cleanup can leave an account exposed.”
“Once attackers hold an application identity, their activity can look like ordinary cloud administration,” he said.
Focus on automation and scale
Microsoft said the activity reflects “a broader shift toward AI-orchestrated attacks,” where threat actors can coordinate operations across cloud environments with “greater speed and scale.”
Tausek said the Azure activity shows coordinated execution, though not necessarily proof that each step was directed by AI.
“I agree with Microsoft’s warning about AI-orchestrated attacks, though the Azure evidence shows coordinated automation rather than proving AI directed each step,” he said.
“Agentic AI can help analysts piece together that sequence and prepare containment while people approve the consequential actions,” he added.
Identity and recovery controls in focus
Microsoft recommended that organizations protect workload identities, enforce least-privilege access and secure backup and recovery resources to reduce risk from similar activity.
Tausek said organizations can reduce exposure by rotating exposed secrets, limiting service principal permissions and protecting backup systems before attackers gain access.
Filipek said response planning across teams is also critical.
“That takes coordination between development, cloud operations and incident response,” he said. “If those teams wait until an outage to work out who owns the credentials, they’ll lose valuable time.”
