Skip to content
Field reportTI-2026-0438

Seven minutes of deletion in an Azure tenant

Microsoft ties JADEPUFFER, reported as the first agentic ransomware operation, to a scripted Azure wipe via two stolen service principals.

2 minThreat IntelligenceFresh · 25 Sept

Microsoft Security Research has published the first detailed view of Azure activity by JADEPUFFER, the actor Sysdig disclosed in July 2026 and reported as the first documented agentic ransomware operation. Microsoft tracks it as Storm-3168. The case involved two compromised service principals in one tenant: one mapped the environment, the other destroyed resources and collected credentials.

The sequence

In early June, the first principal spent about 15 hours and 30 minutes enumerating virtual machines, subscriptions and resource groups, with more than 300 successful reads. About 90 minutes after it started, the second principal enumerated two subscriptions in five seconds. Sixteen hours later it inventoried App Service configuration stores, and less than a second after a failed key request against a storage account that did not exist, the destruction began: more than 150 destructive or credential-related operations in 35 minutes. The deletions themselves lasted about seven minutes and included more than 100 storage account deletion attempts.

Most targeted storage accounts were deleted, along with a Key Vault, a Function App and an App Service plan. Resource locks and account-level deletion protection saved some. Every SQL database deletion failed because the tooling called an unsupported API version, and attempts to remove Site Recovery and Backup protection locks failed too. About 30 minutes after the last deletion, the same principal sent more than 30 successful requests for storage account keys.

The timing, the division of work between principals and five separate tokens for one identity point to automated execution, according to Microsoft. It found no ransom note and could not confirm exfiltration, but calls the mix of destruction, attacks on recovery and key collection consistent with ransomware tactics.

The probable entry point is mundane. The principal's client ID, secret and tenant ID had been posted in plaintext in a public GitHub issue by an employee; the issue was later edited, but the secret stayed readable in its edit history. Microsoft could not confirm that this secret was the one used, and stresses that redacting a leaked credential does not revoke it.

Retold from Microsoft Security. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined