Trusence Every claim has a source
Last updated 28 September 2026 Search Türkçe
← All stories
Security

JadePuffer uses AI agents to automate destructive attacks on Azure

The campaign extends from tenant-wide resource wipes to direct hits on AI datasets and vector stores.

Researchers report that the JadePuffer (tracked by Microsoft as Storm-3168) ransomware group is using AI agents to automate end-to-end attacks against Azure tenants, from reconnaissance through destruction of cloud resources. Sysdig says the campaign, first spotted in July, chains AI-driven tooling for discovery, credential theft, lateral movement, persistence, and data encryption, and has recently expanded to target AI assets such as training datasets and vector databases via a tool called EncForge. Microsoft observed two June intrusions where the attackers used two compromised Azure service principals from the same tenant to map resources, retrieve storage account keys, and then rapidly delete more than 100 Azure Storage accounts and other services including Key Vaults, Function Apps, Virtual Machines, and App Services. Some storage accounts and recovery protections survived because of Azure resource locks, storage-account-level safeguards, failed attempts to delete Azure SQL databases due to an unsupported API version, and unsuccessful efforts to remove Azure Site Recovery locks. Microsoft could not confirm how access was initially obtained but notes that credentials for one service principal had been exposed in a public GitHub issue, and recommends mitigations such as scanning public repos for secrets, enforcing least-privilege Azure RBAC, and enabling cloud workload protection tools.

Why it matters

For Azure customers, this turns cloud configuration mistakes and exposed credentials into a fast path to large-scale data loss. The same tooling that maps and wipes storage and core services is now being pointed at AI training datasets and vector databases, raising the stakes for how tenants secure both traditional workloads and newer AI infrastructure, as well as how rigorously they audit code and repositories for leaked service principal secrets.

Sources

  • BleepingComputer