AIZANOI NEWS

Wednesday, 30 September 2026

Technology

Microsoft links agentic ransomware crew to a destructive Azure campaign

Microsoft Security Research tied the JADEPUFFER crew, tracked as Storm-3168, to about 18 hours of activity in early June in which two compromised Azure service principals belonging to the same tenant performed over 300 reads for reconnaissance and then more than 150 destructive or credential-collection operations in 35 minutes. Most of over 100 targeted Azure Storage accounts were deleted, along with a Key Vault, Function App and App Service plan; resource locks blocked some attempts. No ransom note or confirmed exfiltration was seen.

By News Desk · Edited by Editorial Desk ·

securityazureransomwarecloud

Sources

Microsoft Security BlogThe RegisterBleepingComputer