{"slug": "autonomous-agents-attack-azure-using-compromised-identities-and-destroying", "title": "Autonomous agents attack Azure using compromised identities and destroying resources", "summary": "Microsoft reported that Jadepuffer, an autonomous AI attacker also tracked as Storm-3168, expanded into Azure environments using two compromised service principals in the same tenant to enumerate resources and then carry out more than 150 destructive or credential-related operations over about 35 minutes, including over 100 attempts to delete storage accounts. One identity spent more than 15 hours enumerating virtual machines, subscriptions and resource groups with more than 300 successful read operations, while the main destructive sequence lasted about seven minutes and also deleted an Azure Key Vault, Function App and App Service plan, Microsoft said in a blog post. Microsoft said the combination of resource deletion, interference with recovery mechanisms such as Azure Site Recovery and backup protection locks, and more than 30 successful ListKeys requests about 30 minutes later is consistent with ransomware and extortion tactics, though it observed no ransom note and did not confirm data exfiltration.", "body_md": "Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft.\n\nThe activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration,” Microsoft said in a blog post about Storm-3168, also known as Jadepuffer. Service principals are unique machine identities given to applications running within Azure.\n\n“The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services,” Microsoft said in the blog post, “[Storm-3168: Agentic-driven cloud attacks using compromised service principals](https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/).”\n\nThe campaign was first [reported in July](https://www.csoonline.com/article/4193195/this-ai-agent-autonomously-hacked-a-network-adapted-on-the-fly-and-demanded-a-ransom.html) by Sysdig, which described Jadepuffer as an AI-driven operation capable of executing attack steps autonomously, including exploitation, credential access and destructive activity.\n\nMicrosoft said it observed two compromised service principals in the same tenant, with one performing reconnaissance and the other carrying out discovery, destructive actions and credential collection.\n\nOne of the identities spent more than 15 hours enumerating virtual machines, subscriptions, resource groups and other resources, making more than 300 successful read operations, the company said.\n\nA second service principal enumerated resources across multiple subscriptions within seconds and later conducted additional discovery, Microsoft said.\n\nThe timing and division of activity “strongly indicates automated or scripted execution,” the company said.\n\nNick Tausek, lead security automation architect at Swimlane, said the pattern aligns with earlier observations of the campaign’s behavior.\n\n“Jadepuffer’s earlier database attack showed an AI agent working through an extortion playbook and adjusting when steps failed,” Tausek said. “Microsoft now traces the group into Azure, where compromised service principals mapped resources before a seven-minute burst of destruction.”\n\nAfter the two agents had completed their reconnaissance they began to create mayhem, conducting more than 150 destructive or credential-related operations over about 35 minutes.\n\nThe main destructive sequence lasted about seven minutes and included more than 100 attempts to delete storage accounts, most of which were successful, the blog post said.\n\nThe attackers also deleted an Azure Key Vault, Function App and App Service plan tied to the same resource group, Microsoft said.\n\nAttempts were also made to delete Azure SQL databases and backup-related protections, including Azure Site Recovery locks and backup protection locks, the company said.\n\nTausek said the speed and coordination of the activity could challenge traditional response models.\n\n“At that speed, an AI SOC needs to connect identity activity with cloud changes before the damage spreads,” he said.\n\nAbout 30 minutes after the destructive activity, the same service principal requested storage account access keys, making more than 30 successful ListKeys requests, Microsoft said.\n\nThe requests included storage accounts associated with recovery services, the blog post said.\n\nMicrosoft said the combination of resource deletion, attempts to interfere with recovery mechanisms and credential collection is “consistent with tactics that can support ransomware and extortion operations.”\n\nThe company said it did not observe a ransom note or confirm data exfiltration in the activity.\n\nRoss Filipek, CISO at Corsica Technologies, said the sequence of destruction followed by credential access raises additional response challenges.\n\n“The recovery question here goes beyond rebuilding what was deleted,” Filipek said. “The attackers later requested storage account keys, potentially giving them another route to data.”\n\n“Responders need to establish which identities and keys were touched, then review their use before trusting restored services,” he said.\n\nMicrosoft said it could not confirm the initial access vector but found that credentials associated with a compromised service principal had previously been exposed in plaintext in a public GitHub issue.\n\nThe secret was later removed but remained accessible in the edit history, the company said.\n\n“Publicly exposed credentials remain usable until revoked or rotated; removing the original disclosure alone does not remediate the exposure,” Microsoft said.\n\nFilipek said the finding highlights a common risk in cloud environments.\n\n“A cloud credential remained visible in a GitHub issue’s edit history after someone removed it from the post,” he said. “For an IT team, it’s a useful warning about how a routine cleanup can leave an account exposed.”\n\n“Once attackers hold an application identity, their activity can look like ordinary cloud administration,” he said.\n\nMicrosoft said the activity reflects “a broader shift toward AI-orchestrated attacks,” where threat actors can coordinate operations across cloud environments with “greater speed and scale.”\n\nTausek said the Azure activity shows coordinated execution, though not necessarily proof that each step was directed by AI.\n\n“I agree with Microsoft’s warning about AI-orchestrated attacks, though the Azure evidence shows coordinated automation rather than proving AI directed each step,” he said.\n\n“Agentic AI can help analysts piece together that sequence and prepare containment while people approve the consequential actions,” he added.\n\nMicrosoft recommended that organizations protect workload identities, enforce least-privilege access and secure backup and recovery resources to reduce risk from similar activity.\n\nTausek said organizations can reduce exposure by rotating exposed secrets, limiting service principal permissions and protecting backup systems before attackers gain access.\n\nFilipek said response planning across teams is also critical.\n\n“That takes coordination between development, cloud operations and incident response,” he said. “If those teams wait until an outage to work out who owns the credentials, they’ll lose valuable time.”", "url": "https://wpnews.pro/news/autonomous-agents-attack-azure-using-compromised-identities-and-destroying", "canonical_source": "https://www.csoonline.com/article/4227657/autonomous-agents-attack-azure-using-compromised-identities-and-destroying-resources.html", "published_at": "2026-09-28 14:22:22+00:00", "updated_at": "2026-09-28 14:47:39.589988+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-agents", "ai-policy"], "entities": ["Microsoft", "Jadepuffer", "Storm-3168", "Azure", "Sysdig", "Swimlane", "Nick Tausek", "Ross Filipek"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/autonomous-agents-attack-azure-using-compromised-identities-and-destroying", "markdown": "https://wpnews.pro/news/autonomous-agents-attack-azure-using-compromised-identities-and-destroying.md", "text": "https://wpnews.pro/news/autonomous-agents-attack-azure-using-compromised-identities-and-destroying.txt", "jsonld": "https://wpnews.pro/news/autonomous-agents-attack-azure-using-compromised-identities-and-destroying.jsonld"}}