# JADEPUFFER Leverages Compromised Azure Service Principals for Destructive Cloud Operations

*Published September 30, 2026*
*Source: [https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html](https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html)*

## Executive Summary

JADEPUFFER exploited compromised Azure service principals to conduct destructive operations targeting critical cloud resources. The incident emphasizes the growing trend of AI-driven cyberattacks and the need for enhanced protective measures.

## Article

A recent cybersecurity incident involving the threat actor known as JADEPUFFER has highlighted the vulnerabilities in cloud environments, particularly within Microsoft Azure. The group, tracked by Microsoft as Storm-3168, executed a destructive operation in early June 2026 by compromising Azure service principals. This attack spanned approximately 18 hours and targeted a variety of Azure resources, including Storage Accounts, SQL databases, Key Vaults, and Virtual Machines. Researchers from the Microsoft Security Research team reported that these operations were facilitated by exploiting known security flaws, enabling the attackers to harvest credentials and perform extensive reconnaissance and destructive activities. The attack is notable for its use of ENCFORGE, a Go-based ransomware strain designed for AI infrastructure, which targeted over 180 file extensions, including those relevant to macOS systems. Despite the destructive intent, the attack did not result in a successful data exfiltration or ransom demand. Microsoft observed that the compromised service principals were used for both reconnaissance and destructive operations. The attackers conducted over 300 read operations and multiple destructive actions in a matter of minutes. However, some deletion attempts failed due to unsupported API versions and independent safeguards like resource locks. The exposure of a service principal's credentials in a public GitHub issue was identified as a potential entry point for the attackers. The incident underscores a shift towards AI-driven attacks that require defenders to adopt AI for swift and effective responses.
