Threats · 5h ago

Storm-3168 Used Azure Identities to Wreck Tenants

Microsoft says Storm-3168, also tracked as JADEPUFFER, ran a first-detailed Azure campaign in early June 2026 using two compromised service principals in the same tenant. One identity spent about 15 hours making 300-plus successful read requests across subscriptions, resource groups, and virtual machines; the other followed about 90 minutes later with discovery, credential collection, and destructive activity.

A service principal is an app identity with whatever Azure rights the tenant granted it, so stealing its secret lets an attacker use normal management calls as if they were authorized automation. In this case, Microsoft says the operators targeted Storage Accounts, SQL databases, Key Vaults, Function Apps, virtual machines, App Services, and even recovery protection locks, which means the damage path was tenant-wide cloud control, not a compromised endpoint.

For Azure operators, the useful map is the control plane: if an app secret leaks, the exposure can persist until that credential is revoked or rotated, and recovery assumptions can fail when protection locks are in scope. Host-centric incident response will miss the blast radius when the attacker is living inside workload identity and management APIs.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-25

Editions

Related stories