CRITICALapt·

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The JADEPUFFER threat actor, tracked by Microsoft as Storm-3168, has evolved its tradecraft to conduct destructive operations within Microsoft Azure environments. Attackers leveraged compromised service principals to delete Azure resources over an 18-hour period in early June 2026. This activity highlights a significant risk to cloud infrastructure integrity.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

The JADEPUFFER threat actor (Microsoft’s Storm-3168) has been observed executing destructive actions within Microsoft Azure environments. This activity, occurring over approximately 18 hours in early June 2026, involved the use of compromised service principals to delete Azure resources. This represents an evolution in the actor’s tradecraft, posing a critical threat to cloud infrastructure integrity and availability.

Technical Analysis

JADEPUFFER attackers gained unauthorized access to Azure environments by compromising service principals. These compromised identities were then leveraged to initiate destructive operations, specifically the deletion of Azure resources. The attack unfolded over an 18-hour window, indicating a sustained effort to cause disruption or data loss. The specific methods of initial service principal compromise were not detailed in the available information, but the subsequent actions focused on resource removal.

Detection

Defenders can identify this activity by monitoring Azure Activity Logs and Azure AD Audit Logs for suspicious actions by service principals.

  • Monitor Azure Activity Logs for operationName related to resource deletion (e.g., Microsoft.Resources/subscriptions/resourceGroups/delete, Microsoft.Compute/virtualMachines/delete, Microsoft.Storage/storageAccounts/delete) where the identity.type is ServicePrincipal.
  • Look for an unusual volume or pattern of resource deletion events originating from a single service principal or a cluster of service principals within a short timeframe.
  • Analyze Azure AD Audit Logs for suspicious modifications to service principal permissions or credentials, or sign-ins from unusual geographic locations or IP addresses for service principals.
  • Hunt for service principals performing actions outside their established baseline or expected scope of work.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Azure Resource Group Deletion by Service Principal

title: Azure Resource Group Deletion by Service Principal
id: 9a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d
status: experimental
description: Detects the deletion of an Azure Resource Group by a Service Principal, which could indicate a compromised identity or destructive activity.
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName: 'Microsoft.Resources/subscriptions/resourceGroups/delete'
    identity.type: 'ServicePrincipal'
  condition: selection
level: critical

Suspicious Azure Resource Deletion by Service Principal

title: Suspicious Azure Resource Deletion by Service Principal
id: 0f1e2d3c-4b5a-6f7e-8d9c-a0b1c2d3e4f5
status: experimental
description: Identifies general resource deletion operations performed by a Service Principal in Azure, potentially indicating a compromised account or malicious activity.
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName|contains: '/delete'
    identity.type: 'ServicePrincipal'
  condition: selection
level: high

Mitigations

  1. Implement Strong Authentication for Service Principals: Where possible, use managed identities or certificate-based authentication for service principals instead of secrets. If secrets are necessary, enforce strong, regularly rotated secrets.
  2. Apply Least Privilege: Grant service principals only the minimum necessary permissions required for their function. Regularly review and audit assigned roles and permissions.
  3. Monitor Azure Activity and Audit Logs: Implement continuous monitoring for resource deletion events, service principal activity, and changes to permissions. Integrate these logs with a SIEM for alert generation and correlation.
  4. Enable Azure Resource Locks: Apply resource locks (CanNotDelete, ReadOnly) to critical Azure resources to prevent accidental or malicious deletion.
  5. Regularly Audit Service Principals: Periodically review all service principals in your Azure AD tenant, their assigned permissions, and their activity to identify dormant or over-privileged accounts.

References

  • https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,543 input / 1,123 output tokens ·
Reviewed and approved by a human analyst before publication
#apt#apt#azure#cloud#critical#destructive