Cybercriminal JADEPUFFER has been spotted carrying out destructive operations in a Microsoft Azure, leveraging compromised service principals to delete critical resources. The attack, tracked by Microsoft under the codename Storm-3168, is an evolution of the threat actor’s tactics and lasted approximately 18 hours in early June 2026. The incident highlights the increasing risk faced by organizations using cloud services, particularly when administrative credentials are not adequately protected.
See also: CVE-2026-56163: Critical EoP in Azure Kubernetes Service (AKS) – Mitigated by Microsoft

Researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research, analyzed the malicious actions in detail. The attacks targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines , and App Services. The success of the attack relied on the misuse of legitimate service identities, which makes detection particularly difficult for traditional security systems.
JADEPUFFER detected by cybersecurity firm Sysdig, which described it as the first ransomware executed end-to-end using a Large Language Model (LLM). The initial attack exploited a known vulnerability in Langflow (CVE-2025-3248) to gain access, collected credentials, penetrated deeper into the network, encrypted Nacos, deleted the original database tables, and left a ransom note demanding payment in Bitcoin.
JADEPUFFER and the ENCFORGE tool: Ransomware for AI infrastructures
While the initial attack used MySQL ’s built-in AES_ENCRYPT() function for the encryption step, the same Langflow instance was targeted again by the threat actor, this time with a compiled Go- based ransomware , codenamed ENCFORGE . ENCFORGE is specifically designed for AI infrastructures, scanning nearly 180 file extensions covering model checkpoints , vector databases , training datasets and embedding indices . In addition, it targets macOS -specific files such as Keychain stores , Xcode project files , as well as Apple Pages and Numbers documents .
Sysdig commented : “An autonomous agent thought about its targets, collected and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its intentions all the while.” The company noted that none of the individual techniques were new or sophisticated, but what stands out is that an AI model connected them into a comprehensive ransomware against neglected infrastructure exposed to the internet.
This development is particularly worrying for the cybersecurity industry, as it signals a new era where artificial intelligence is not only used defensively but also offensively. Organizations managing AI infrastructure need to rethink their security models, considering that training data and model checkpoints are now prime targets for extortionists.
See also: Microsoft reveals Storm-2949 attack on Azure Cloud and Microsoft 365

Analysis of the JADEPUFFER attack on Azure: Timeline and technical details
Microsoft has identified two compromised service principals associated with the same tenant . The first was used for resource identification and discovery, while the second was used for destructive operations and credential harvesting. The enumeration activity targeted Azure Virtual Machines , subscriptions, resource groups, and resources for nearly 16 hours , performing over 300 read operations during that time.
The second compromised service principal began its own discovery operations 90 minutes later, enumerating virtual machines and resource groups across two subscriptions in just 5 seconds. After 16 hours, the second service principal successfully enumerated Azure App Service configuration stores, likely in an attempt to identify exposed credentials. It then performed over 150 destructive or credential harvesting actions in just 35 minutes.
The destructive sequence lasted approximately 7 minutes and included over 100 attempts to delete storage accounts. Also targeted were an Azure Key Vault, a Function App , and an App Service plan, as well as multiple Azure SQL databases. However, each attempt to delete the database failed due to using an unsupported API version for the Azure SQL database.
“ Most of the Azure Storage accounts targeted by the threat actor were successfully deleted ,” Microsoft said . “ However, Azure resource locks and storage account-level deletion protection blocked deletion attempts for some of the storage accounts, demonstrating the value of independent security mechanisms that remain effective even when a compromised identity has broad administrative permissions .”
How to protect yourself from JADEPUFFER attacks on Azure
The incident highlights the importance of implementing resource locks on critical Azure, as they were effective even when the attacker had administrative privileges. Organizations should implement the principle of least privilegeforall service principals, limiting permissions to only those strictly necessary for their operation. In addition, regularly reviewing and auditing service principal can prevent the misuse of compromised identities.
Enabling Microsoft Defender for Cloud and monitoring for anomalous activity through Azure Monitor and Microsoft Sentinel are critical steps for early detection of such attacks. In particular, monitoring bulk read or delete operations by service principals over a short period of time can be a significant indicator of a breach. Security teams should also ensure that Azure Key Vaults and storage accounts have appropriate resource locks and that soft delete settings are enabled.
See also: First VPN Service: US sanctions for supporting ransomware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The JADEPUFFER is a prime example of the evolution of cyberthreats in the age of artificial intelligence. The ability of an AI-enhanced threat actor to coordinate complex operations autonomously, make decisions in real time, and adapt to the target’s defense capabilities represents a fundamental shift in the cyberthreat landscape. Organizations operating in cloud must invest in advanced detection and response solutions while reinforcing the security fundamentals that have proven effective even in this sophisticated attack.
