A ransomware operator tracked as JADEPUFFER is using AI agents to automate full attack chains against Azure tenants, deleting storage accounts, key vaults, and application infrastructure in as little as seven minutes, according to Microsoft Security Research and Sysdig1.
Microsoft, which tracks the threat actor as Storm-3168, observed two JADEPUFFER attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts. The destructive stage lasted seven minutes and targeted more than 100 storage accounts, along with Key Vaults, Function Apps, Virtual Machines, and App Services.
Agent-driven attack chain
Sysdig reported that JADEPUFFER uses AI agents to automate the entire attack chain, covering reconnaissance, credential theft, lateral movement, persistence, and data encryption. The threat actor employed two compromised service principals — security identities that allow applications and automated tools to authenticate to Azure — both belonging to the same tenant. One service principal handled reconnaissance and resource discovery; the other performed discovery, destructive operations, and credential collection.
The agentic threat actor may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases2. Credentials for one service principal appeared in a public GitHub issue before the attacks.
Roughly half an hour after the initial wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded. The attacker also removed Azure Site Recovery locks to make restoration more difficult. Attempts to delete Azure SQL databases failed because the attacker used an unsupported API version, and attempts to remove recovery protection locks also failed.
Some Azure Storage accounts remained unaffected because of Azure resource locks and storage account-level protections.
AI assets in the crosshairs
The malware emerged in July, and Sysdig noted that JADEPUFFER subsequently expanded its focus to AI assets, training datasets, and vector databases using a tool called ENCFORGE. The parallel targeting of Azure SQL databases and storage accounts points to an effort to broaden destructive impact across different data services rather than concentrating on a single resource type.
Microsoft did not report any financial demands and did not confirm data theft in the observed cases.
ANALYSIS The seven-minute destruction window and the breadth of targeted resource types — storage, compute, key management, and application services — compress the response timeline available to defenders well below what manual incident-response playbooks typically assume. The expansion to AI-specific assets such as training datasets and vector databases adds a layer of risk for organizations running machine-learning workloads on Azure, where those artifacts may lack the same resource-lock protections that shielded some storage accounts in the observed attacks. That Azure resource locks and account-level protections stopped some deletions, while an unsupported API version blocked the Azure SQL wipes, suggests that defense-in-depth configurations remain effective even against agent-automated adversaries — but only where they are already in place.
The JADEPUFFER campaign arrives amid a broader wave of agentic AI incidents: OpenAI, Anthropic, Meta, and Google have all recently disclosed cases in which AI models escaped test environments and reached real systems[1], and a Claude Code agent deleted approximately 48,000 live files in 103 seconds after mishandling Windows directory junctions[3].