{"id":2064,"date":"2026-09-29T10:33:01","date_gmt":"2026-09-29T05:03:01","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2064"},"modified":"2026-10-05T09:46:48","modified_gmt":"2026-10-05T04:16:48","slug":"jadepuffer-azure-attack-storm-3168-hits-service-principals","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/","title":{"rendered":"JadePuffer Azure Attack: Storm-3168 Hits Service Principals"},"content":{"rendered":"<p>Microsoft has linked new Azure destruction activity to JadePuffer. Sysdig first documented JadePuffer in July 2026 as an agent-driven ransomware operator. In the JadePuffer Azure attack, Microsoft observed two compromised service principals inside one tenant. The identities carried out reconnaissance, deleted cloud resources, and collected storage account keys. Microsoft tracks this activity as Storm-3168.<\/p>\n<p>Service principals are machine identities. They hold Azure permissions without a human login to flag. Once an attacker controls one, it can enumerate resources, delete infrastructure, and pull credentials at machine speed. Microsoft&#8217;s findings describe a seven-minute destructive sequence. The sequence hit more than 100 storage accounts, plus Key Vaults, Function Apps, and an App Service plan.<\/p>\n<p>This is not an isolated incident. JadePuffer already automated a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-ransomware-in-cybersecurity\/\">ransomware<\/a> attack against a production database server in July. Storm-3168&#8217;s Azure activity shows the same automation now targeting cloud identity and infrastructure.<\/p>\n<h2>How two service principals split the work<\/h2>\n<p>Microsoft found that both compromised service principals belonged to the same Azure tenant, and each carried a distinct job.<\/p>\n<ul>\n<li>The first service principal enumerated virtual machines, subscriptions, resource groups, and resources for roughly 15 hours and 30 minutes. It completed over 300 successful read operations, giving the attacker broad visibility into the environment.<\/li>\n<li>The second service principal started about 90 minutes later. It enumerated virtual machines and resource groups across two subscriptions in just five seconds.<\/li>\n<\/ul>\n<p>Both identities used Storm-3168 linked infrastructure, the same network fingerprint, and the identical user agent string python-requests\/2.34.2. That overlap points to scripted, coordinated execution rather than manual operator activity.<\/p>\n<p>Sixteen hours after that enumeration, the second service principal probed Azure App Service configuration stores, likely searching for exposed credentials. It also tried and failed to locate Azure OpenSearch resources. Seventy seconds later, it attempted a ListKey operation against a storage account that did not exist. Destructive activity began less than one second after that failed call.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-classification.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Classification?<\/h4><p>Threat classification organizes and prioritizes security alerts for faster response.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-classification\/\" aria-label=\"What is Threat Classification?\"><\/a><\/div><\/div><\/div>\n<h2>A seven-minute destructive sequence<\/h2>\n<p>The second service principal attempted more than 150 destructive or credential-related operations over 35 minutes. The core wipe itself took about seven minutes.<\/p>\n<ul>\n<li>It attempted 100+ storage account deletions. Most succeeded, but Azure resource locks and storage account-level deletion protection blocked a smaller number.<\/li>\n<li>It deleted a Key Vault, a Function App, and an App Service plan, all in the same resource group.<\/li>\n<li>It attempted to delete multiple Azure SQL databases in parallel with the storage deletions. Every attempt failed because the request used an unsupported API version for that resource type.<\/li>\n<li>It attempted to delete Azure Site Recovery locks and an Azure Backup protection lock. These attempts also failed.<\/li>\n<\/ul>\n<p>Roughly 30 minutes after the destructive activity ended, the same service principal returned. It requested an inventory of storage accounts, then sent more than 30 successful ListKeys requests. Some of the targeted accounts were tied to Azure Site Recovery.<\/p>\n<p>Microsoft&#8217;s analysis found that the attacker&#8217;s actions matched the service principal&#8217;s existing Azure RBAC assignments. A group-granted Storage Account Contributor role authorized the storage deletions. Direct Contributor access authorized the Key Vault, Function App, and App Service plan deletions. Direct SQL DB Contributor access authorized the SQL deletion attempts, which failed for the technical reason above rather than a permissions gap.<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 28.8583%; text-align: left;\"><strong>Azure Resource<\/strong><\/th>\n<th style=\"width: 38.6892%; text-align: left;\"><strong>Attack Outcome<\/strong><\/th>\n<th style=\"width: 31.3953%; text-align: left;\"><strong>Operational Priority<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 28.8583%;\">Storage accounts (100+)<\/td>\n<td style=\"width: 38.6892%;\">Most deleted; a smaller number blocked by resource locks and deletion protection<\/td>\n<td style=\"width: 31.3953%;\">Critical: verify locks, rotate keys<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.8583%;\">Key Vault, Function App, App Service plan<\/td>\n<td style=\"width: 38.6892%;\">Deleted<\/td>\n<td style=\"width: 31.3953%;\">High: restore from backup, audit secrets<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.8583%;\">Azure SQL databases<\/td>\n<td style=\"width: 38.6892%;\">Deletion attempted, failed due to unsupported API version<\/td>\n<td style=\"width: 31.3953%;\">Medium: monitor for retry attempts<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.8583%;\">Site Recovery locks, Backup protection lock<\/td>\n<td style=\"width: 38.6892%;\">Deletion attempted, failed<\/td>\n<td style=\"width: 31.3953%;\">High: protect recovery infrastructure<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.8583%;\">Storage account keys<\/td>\n<td style=\"width: 38.6892%;\">30+ successful ListKeys requests<\/td>\n<td style=\"width: 31.3953%;\">Critical: rotate keys immediately<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Why this looks like ransomware, not just a wiper<\/h2>\n<p>Microsoft assessed that the combination of destruction, recovery-lock targeting, and credential collection is consistent with tactics that support ransomware and extortion. Several details point in that direction:<\/p>\n<ul>\n<li>The attacker targeted storage accounts and Azure Storage assets with Terraform- and backup-themed names, suggesting an attempt to weaken recovery options.<\/li>\n<li>The attacker also targeted Azure SQL databases in parallel with storage deletions, broadening the destructive scope across data services rather than focusing on one type.<\/li>\n<li>The attacker collected storage account keys after the wipe, which could support data access or exfiltration in a later stage.<\/li>\n<\/ul>\n<p>Public reporting does not confirm a ransom demand in this campaign. Microsoft also did not confirm data exfiltration in the activity it observed.<\/p>\n<h2>A leaked secret and an unresolved entry point<\/h2>\n<p>Microsoft could not determine exactly how the service principal was first compromised. Here is what investigators did find:<\/p>\n<ul>\n<li>The client ID, client secret, and tenant ID for one service principal appeared in plaintext in a public GitHub issue posted by an employee of the affected organization.<\/li>\n<li>Someone later edited the issue to remove the secret, but the credential remained visible through the issue&#8217;s public edit history.<\/li>\n<li>Microsoft could not confirm whether this specific secret enabled the observed activity.<\/li>\n<\/ul>\n<p>Separately, Microsoft has tracked Storm-3168-linked infrastructure probing Azure App Service instances across multiple customers since the start of the year. That probing targeted paths associated with WordPress administration, PHP-CGI, and LangFlow&#8217;s code validation endpoint.<\/p>\n<p>Microsoft found no overlap between those probed App Service targets and the affected subscriptions here, and no credential path from App Service to Azure Resource Manager for this tenant. The two activities appear related to the same actor&#8217;s broader operations, but the App Service probing is not confirmed as the entry point for this specific attack.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore major cybersecurity frameworks and how UEM strengthens compliance, visibility, and endpoint protection across organizations.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Reducing the human side of machine-identity risk<\/h2>\n<p>The exposed credential in this case did not leak from Azure itself. It leaked from a developer&#8217;s GitHub activity, which puts part of the exposure squarely on endpoint and workflow hygiene. <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> and <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can support that layer without touching Azure&#8217;s own control plane.<\/p>\n<h3>Hexnode UEM<\/h3>\n<ul>\n<li>Enforces configuration management and application allowlisting\/blocklisting across developer and admin workstations, with OS patch management for Windows, macOS, and Linux, and automated third-party app patching for Windows endpoints.<\/li>\n<li>Reports device compliance to Microsoft Entra ID for Android, iOS, and macOS devices, so device-aware access policies can block non-compliant devices from reaching sensitive resources.<\/li>\n<\/ul>\n<h3>Hexnode XDR<\/h3>\n<ul>\n<li>Investigates suspicious activity on managed Windows and macOS endpoints, helping flag unusual local behavior around credential files, Git tooling, or configuration stores before a secret reaches a public repository.<\/li>\n<li>Lets admins kill a harmful process, quarantine flagged files, or isolate a suspicious endpoint, containing local risk while an investigation is underway.<\/li>\n<\/ul>\n<p>None of this reaches into Azure Resource Manager, service principals, or storage accounts. Hexnode does not detect JadePuffer, patch Azure services, or monitor cloud-side API activity. It complements the credential rotation, <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-role-based-access-control-rbac\/\">RBAC<\/a> review, and Defender for Cloud protections that Azure teams must still manage directly.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is a service principal, and why can compromising one cause so much damage?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>A service principal is a security identity that lets an application or automated tool authenticate to Azure. It often carries broad permissions across an environment, so a compromised service principal can act like an administrator without triggering a human sign-in alert.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Did JadePuffer steal data during this Azure campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Microsoft did not confirm data exfiltration in the activity it reviewed. The credential collection stage, including the storage key requests, could support data theft in a later phase, but reviewed sources do not establish that theft occurred here.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">If a secret was posted to GitHub and then removed, is it still a risk?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Editing or deleting a public post does not invalidate the credential. Copies can persist in edit history, caches, forks, or logs, so any exposed secret should be rotated immediately rather than treated as resolved once it is no longer visible.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n<h3>Conclusion<\/h3>\n<p>JadePuffer&#8217;s Azure activity shows ransomware tradecraft moving into cloud identity. Compromised service principals let an automated operator discover resources, delete infrastructure, and harvest credentials without a human account in sight.<\/p>\n<p>Enterprises should treat workload identities as an attack surface, not background plumbing. Rotate exposed secrets immediately, apply least privilege to service principals, and monitor destructive cloud operations with the same urgency given to endpoint ransomware.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Machine identities are now ransomware targets. <\/h5><p>Get practical guidance on securing endpoints behind your cloud identities.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has linked new Azure destruction activity to JadePuffer. Sysdig first documented JadePuffer in July&#8230;<\/p>\n","protected":false},"author":5,"featured_media":2085,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11,19],"class_list":["post-2064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","category-cloud-and-saas","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>JadePuffer Azure Attack: Storm-3168 Service Principal Abuse<\/title>\n<meta name=\"description\" content=\"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"JadePuffer Azure Attack: Storm-3168 Service Principal Abuse\" \/>\n<meta property=\"og:description\" content=\"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T05:03:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-05T04:16:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"JadePuffer Azure Attack: Storm-3168 Hits Service Principals\",\"datePublished\":\"2026-09-29T05:03:01+00:00\",\"dateModified\":\"2026-10-05T04:16:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/\"},\"wordCount\":1418,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/jadepuffer-azure-attack.jpeg?format=webp\",\"articleSection\":[\"Ransomware\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/\",\"name\":\"JadePuffer Azure Attack: Storm-3168 Service Principal Abuse\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/jadepuffer-azure-attack.jpeg?format=webp\",\"datePublished\":\"2026-09-29T05:03:01+00:00\",\"dateModified\":\"2026-10-05T04:16:48+00:00\",\"description\":\"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/jadepuffer-azure-attack.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/jadepuffer-azure-attack.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"jadepuffer azure attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jadepuffer-azure-attack-storm-3168-hits-service-principals\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"JadePuffer Azure Attack: Storm-3168 Hits Service Principals\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"JadePuffer Azure Attack: Storm-3168 Service Principal Abuse","description":"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/","og_locale":"en_US","og_type":"article","og_title":"JadePuffer Azure Attack: Storm-3168 Service Principal Abuse","og_description":"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-29T05:03:01+00:00","article_modified_time":"2026-10-05T04:16:48+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"JadePuffer Azure Attack: Storm-3168 Hits Service Principals","datePublished":"2026-09-29T05:03:01+00:00","dateModified":"2026-10-05T04:16:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/"},"wordCount":1418,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp","articleSection":["Ransomware","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/","url":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/","name":"JadePuffer Azure Attack: Storm-3168 Service Principal Abuse","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp","datePublished":"2026-09-29T05:03:01+00:00","dateModified":"2026-10-05T04:16:48+00:00","description":"Storm-3168 used compromised service principals in the JadePuffer Azure attack to delete cloud resources and collect storage account keys.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/jadepuffer-azure-attack.jpeg?format=webp","width":1340,"height":700,"caption":"jadepuffer azure attack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/jadepuffer-azure-attack-storm-3168-hits-service-principals\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"JadePuffer Azure Attack: Storm-3168 Hits Service Principals"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2064"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2064\/revisions"}],"predecessor-version":[{"id":2129,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2064\/revisions\/2129"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2085"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}