#Storm3168
Microsoft has identified a new ransomware strain, Storm-3168, that uses stolen Azure AD identities to delete storage accounts and harvest keys. #Storm3168 #ransomware #AzureAD #storage https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage and harvest keys.
securityaffairs.com
September 29, 2026 at 8:30 AM
JadePuffer is an AI-driven ransomware campaign targeting Azure tenants with automated recon, credential theft, lateral movement, and destruction of cloud resources, including storage, Key Vault, VMs, and App Services. #JadePuffer #Azure #Storm3168
JadePuffer Agentic AI Attacks Target Azure, Destroy Cloud Resources
JadePuffer is a new AI-driven ransomware operator targeting Azure tenants with automated reconnaissance, credential theft, lateral movement, and destructive actions against cloud resources. Microsoft linked the activity to Storm-3168, which used compromised service principals to delete storage accounts, weaken recovery protections, and expand attacks to AI assets such as training data and vector databases. #JadePuffer #Storm3168 #Azure #EncForge #Microsoft
www.hendryadrian.com
September 28, 2026 at 5:45 PM
In two June attacks, the JadePuffer group deleted most of the Azure storage it targeted and removed some recovery safeguards.

Data theft has not been confirmed; th…

https://en.hacks.gr/se-dyo-epitheseis-sto-azure-i-jadepuffer-diegrapse-toys-perissoteroys-stochoys-tis/

#Microsoft #Azure #Storm3168
September 29, 2026 at 2:05 AM