JadePuffer is a new AI-driven ransomware operator targeting Azure tenants with automated reconnaissance, credential theft, lateral movement, and destructive actions against cloud resources. Microsoft linked the activity to Storm-3168, which used compromised service principals to delete storage accounts, weaken recovery protections, and expand attacks to AI assets such as training data and vector databases. #JadePuffer #Storm3168 #Azure #EncForge #Microsoft
Keypoints
- JadePuffer uses AI agents to automate the full attack chain.
- The attacker targeted Azure Storage, Key Vault, Function Apps, Virtual Machines, and App Services.
- Microsoft says the threat actor is tracked as Storm-3168.
- Two compromised service principals were used for discovery and destructive actions.
- Attackers tried to remove backup protections and collect storage account keys.