The emergence of JADEPUFFER, a sophisticated threat actor tracked by Microsoft as Storm-3168, represents a critical inflection point in the landscape of cloud-based cyber warfare. By leveraging large language models (LLMs) to orchestrate end-to-end ransomware and destructive operations, this adversary has demonstrated how artificial intelligence can be weaponized to navigate, exploit, and dismantle complex cloud infrastructures with unprecedented mechanical efficiency. In a series of incursions observed in early June 2026, the group utilized compromised service principals to target high-value assets across Microsoft Azure, signaling a transition toward autonomous, agent-led cyber campaigns.
The Evolution of Storm-3168 Tradecraft
Initially identified by security researchers at Sysdig, JADEPUFFER gained notoriety for pioneering the use of LLMs to manage the entire lifecycle of a ransomware operation. Unlike traditional manual intrusions, which require significant human interaction at every phase of the attack chain, the JADEPUFFER model uses autonomous agents to perform reconnaissance, credential harvesting, lateral movement, and final-stage payload deployment.
Microsoft’s internal analysis, released by researchers Yossi Weizman and Tushar Mudi, details a significant evolution in the group’s tradecraft. While earlier attacks focused on exploiting specific vulnerabilities like the Langflow remote code execution (RCE) flaw (CVE-2025-3248), the June 2026 campaign revealed a more calculated, multi-stage approach within the Azure ecosystem. By abusing service principals—identities created for applications to access resources—the attackers gained a foothold that allowed them to bypass traditional user-based authentication hurdles.
Chronology of the June 2026 Campaign
The breach, which unfolded over approximately 18 hours, showcased the speed at which automated agents can operate within a cloud environment. The activity was characterized by a distinct division of labor between two compromised service principals operating within the same tenant.

Phase 1: Reconnaissance and Discovery (0–16 Hours)
The primary service principal initiated a systematic enumeration of the target environment. Over the course of 16 hours, the actor performed over 300 distinct read operations. The scope of this reconnaissance was extensive, targeting Azure Virtual Machines, specific resource groups, and subscription configurations. This phase was designed to map the terrain, identifying potential points of failure and high-value data repositories.
Phase 2: Escalation and Secondary Discovery (16–17.5 Hours)
Approximately 90 minutes after the initial reconnaissance, a second service principal was introduced into the environment. This secondary actor performed rapid discovery across two different subscriptions, completing its assessment in under five seconds. During this window, the attacker focused on Azure App Service configuration stores, a common repository for developers to inadvertently leave plaintext credentials, API keys, and connection strings.
Phase 3: The Destructive Sequence (17.5–18 Hours)
Following the successful harvest of credentials, the threat actor transitioned into a destructive mode. In a brief, intense window of just 35 minutes, the attackers executed over 150 operations related to credential collection and resource deletion. The actual "scorched earth" sequence was remarkably efficient, lasting only seven minutes. During this time, the actor attempted to delete over 100 storage accounts, targeting critical infrastructure including Key Vaults, Function Apps, and various App Service plans.
Tactical Analysis of the Attack
The sophistication of the JADEPUFFER campaign lies in its goal-oriented reasoning. Sysdig’s initial reports highlighted that the AI agent acted with a degree of autonomy that allowed it to narrate its own intent, adapting to obstacles in real-time.
A critical component of this campaign was the deployment of the ENCFORGE ransomware strain. Specifically engineered for AI-centric infrastructure, ENCFORGE is designed to scan for and encrypt approximately 180 file types. Its primary targets include model checkpoints, vector databases, training datasets, and embedding indices—the intellectual property that defines modern AI models. Furthermore, the malware is configured to compromise local developer environments by targeting macOS-centric files, including Keychain stores, Xcode projects, and productivity documents, effectively crippling the victim’s ability to respond to or recover from the attack.

Resilience and Mitigation: The Role of Resource Locks
Despite the destructive intent of Storm-3168, the attack met with partial failure, providing a vital lesson in cloud security architecture. Microsoft reported that while many storage accounts were successfully wiped, several remained intact. These accounts were protected by "Azure Resource Locks" and storage-level deletion protection.
This detail underscores a fundamental principle of cloud defense: the necessity of independent, granular safeguards. Even when a compromised identity possesses broad administrative privileges, properly implemented resource locks act as a "circuit breaker," preventing irreversible damage. This layer of defense proved effective even when the underlying identity (the service principal) had been fully compromised by the threat actor.
Root Cause: The Persistence of Human Error
The investigation revealed that the breach was not caused by a zero-day exploit in Azure’s infrastructure, but rather by a failure in basic credential hygiene. The client ID, client secret, and tenant ID associated with the compromised service principal had been exposed in a public GitHub issue by an employee.
Although the organization attempted to remediate the exposure by deleting the issue, the information remained preserved in the public edit history. This incident serves as a stark reminder that in the era of AI-driven threats, the "surface area" of a vulnerability includes not just code, but the entire digital footprint of an organization, including its version control history and public-facing documentation.
Broader Implications for Enterprise Security
The activities of JADEPUFFER signal a shift toward "agentic-driven" cloud attacks. As threat actors become more adept at utilizing LLMs to chain together common, non-sophisticated techniques, the velocity of attacks will likely increase. When an AI can coordinate across multiple service principals to perform simultaneous reconnaissance and destruction, manual defense mechanisms are often too slow to intervene.

Microsoft has observed persistent, automated probing from infrastructure linked to Storm-3168 across various Azure App Services for multiple customers. These attempts suggest that the actor is actively hunting for similar misconfigurations in other organizations.
To counter this, security professionals are being urged to adopt a proactive, AI-assisted defensive posture. "As these capabilities evolve, defenders must similarly use AI to investigate and respond across large environments," Microsoft stated in its post-incident analysis. This includes:
- Automated Secret Scanning: Implementing tools that continuously scan repositories for sensitive credentials, not just in current files but in the entire commit history.
- Identity Hardening: Utilizing conditional access policies that restrict service principals to specific IP ranges or time-bound sessions.
- Resource Protection: Applying "CanNotDelete" resource locks to critical storage accounts, databases, and key vaults, ensuring that even administrative accounts cannot perform mass-deletion operations without an additional authorization step.
- Behavioral Monitoring: Utilizing cloud-native security tools to detect anomalous patterns of enumeration, such as the rapid, high-volume read operations observed during the 16-hour reconnaissance phase of the JADEPUFFER attack.
Conclusion
The JADEPUFFER incident is a watershed moment for cloud security. It demonstrates that the future of cybercrime is not necessarily found in highly complex, never-before-seen malware, but in the intelligent, rapid coordination of well-understood exploits. By leveraging AI to automate the mundane aspects of reconnaissance and lateral movement, actors like Storm-3168 are effectively scaling their operations to match the vastness of the cloud. For the modern enterprise, the defense against such threats requires a combination of strict identity governance, robust infrastructure protection, and the integration of AI-driven security orchestration to ensure that human-speed responses can keep pace with machine-speed attacks.
