JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The JADEPUFFER threat actor, tracked by Microsoft as Storm-3168, has evolved its tradecraft to conduct destructive operations within Microsoft Azure environments. Attackers leveraged compromised service principals to delete Azure resources over an 18-hour period in early June 2026. This activity highlights a significant risk to cloud infrastructure integrity.
Overview
The JADEPUFFER threat actor (Microsoft’s Storm-3168) has been observed executing destructive actions within Microsoft Azure environments. This activity, occurring over approximately 18 hours in early June 2026, involved the use of compromised service principals to delete Azure resources. This represents an evolution in the actor’s tradecraft, posing a critical threat to cloud infrastructure integrity and availability.
Technical Analysis
JADEPUFFER attackers gained unauthorized access to Azure environments by compromising service principals. These compromised identities were then leveraged to initiate destructive operations, specifically the deletion of Azure resources. The attack unfolded over an 18-hour window, indicating a sustained effort to cause disruption or data loss. The specific methods of initial service principal compromise were not detailed in the available information, but the subsequent actions focused on resource removal.
Detection
Defenders can identify this activity by monitoring Azure Activity Logs and Azure AD Audit Logs for suspicious actions by service principals.
- Monitor Azure Activity Logs for
operationNamerelated to resource deletion (e.g.,Microsoft.Resources/subscriptions/resourceGroups/delete,Microsoft.Compute/virtualMachines/delete,Microsoft.Storage/storageAccounts/delete) where theidentity.typeisServicePrincipal. - Look for an unusual volume or pattern of resource deletion events originating from a single service principal or a cluster of service principals within a short timeframe.
- Analyze Azure AD Audit Logs for suspicious modifications to service principal permissions or credentials, or sign-ins from unusual geographic locations or IP addresses for service principals.
- Hunt for service principals performing actions outside their established baseline or expected scope of work.
Sigma Detection Rules
Azure Resource Group Deletion by Service Principal
title: Azure Resource Group Deletion by Service Principal
id: 9a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d
status: experimental
description: Detects the deletion of an Azure Resource Group by a Service Principal, which could indicate a compromised identity or destructive activity.
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName: 'Microsoft.Resources/subscriptions/resourceGroups/delete'
identity.type: 'ServicePrincipal'
condition: selection
level: critical
Suspicious Azure Resource Deletion by Service Principal
title: Suspicious Azure Resource Deletion by Service Principal
id: 0f1e2d3c-4b5a-6f7e-8d9c-a0b1c2d3e4f5
status: experimental
description: Identifies general resource deletion operations performed by a Service Principal in Azure, potentially indicating a compromised account or malicious activity.
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName|contains: '/delete'
identity.type: 'ServicePrincipal'
condition: selection
level: high
Mitigations
- Implement Strong Authentication for Service Principals: Where possible, use managed identities or certificate-based authentication for service principals instead of secrets. If secrets are necessary, enforce strong, regularly rotated secrets.
- Apply Least Privilege: Grant service principals only the minimum necessary permissions required for their function. Regularly review and audit assigned roles and permissions.
- Monitor Azure Activity and Audit Logs: Implement continuous monitoring for resource deletion events, service principal activity, and changes to permissions. Integrate these logs with a SIEM for alert generation and correlation.
- Enable Azure Resource Locks: Apply resource locks (CanNotDelete, ReadOnly) to critical Azure resources to prevent accidental or malicious deletion.
- Regularly Audit Service Principals: Periodically review all service principals in your Azure AD tenant, their assigned permissions, and their activity to identify dormant or over-privileged accounts.
References
- https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
Generated by
gemini-2.5-flash ·1,543 input / 1,123 output tokens ·
Reviewed and approved by a human analyst before publication