Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #7
Storm-3168 Wiped Azure Resources Using Stolen Service Principals
Original: 🤖 Storm-3168/JADEPUFFER abused compromised Azure service principals to run destructive operations — deleting resources o
The threat actor tracked as Storm-3168, associated with the JADEPUFFER campaign, abused compromised Azure service principals to carry out destructive operations, deleting cloud resources over roughly 18 hours in early June 2026. Microsoft assesses the activity as an evolution of the actor's tradecraft, and security teams are being urged to review service principal permissions.
Why now: Microsoft's assessment of an evolving cloud attack technique has prompted security practitioners to warn about service principal abuse and destructive Azure operations.
Storm-3168MicrosoftAzureJADEPUFFER
Evidence
- 🤖 Storm-3168/JADEPUFFER abused compromised Azure service principals to run destructive operations — deleting resources over ~18h in early June 2026. Microsoft calls it an evolution of the actor's tradecraft. 🔗 https:// thehackernews.com/2026/09/jade… · cloud@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/227874