Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. https://msft.it/6047a9lcd Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
Microsoft’s analysis makes the speed and scope of this attack particularly clear. For a critical-service operator, I would test the consequences beyond deleted cloud resources: which alarms, shared records, or recovery instructions become unavailable, and which decisions must continue locally? Service-principal permissions determine much of that exposure. A useful exercise would trace each privileged identity to the operational services it can affect, then rehearse a rapid destructive-action alert alongside a loss of cloud visibility. Could the team contain the identity and maintain safe operations before it has a complete picture of what was deleted?
This is now more worrying and would hear quite often - the agentic attack. The future cloud attack may have no malware, no interactive shell and almost no human attacker activity but just legitimate APIs being invoked by identities the environment believes are authorised.
The service principal angle is striking: two compromised identities coordinated to carry out discovery, destruction, and credential collection in under seven minutes. This underlines how workload identities - OAuth connections, service principals, app registrations - are now primary attack vectors, yet still among the least monitored assets in most cloud environments.