BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Storm-3168: AI-Orchestrated Azure Attacks Hit Service Principals

Microsoft's Storm-3168 used AI to orchestrate a destructive Azure ransomware attack.

  • Microsoft’s Storm-3168 used AI orchestration and compromised service principals to launch a destructive ransomware attack on Azure, demanding Bitcoin payment.
  • The attack deleted storage accounts, databases, and recovery resources, with many deletions successful despite some safeguards.
  • Exposed credentials in a public GitHub issue facilitated the intrusion, highlighting AI-driven threats evolving faster than traditional defenses.

In early June 2026, the threat actor known as JADEPUFFER, tracked by Microsoft as Storm-3168, executed a destructive ransomware attack on an Azure environment using compromised service principals. The operation spanned roughly 18 hours, targeting Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, and more, according to Microsoft’s analysis. The actor left a ransom note demanding Bitcoin payment, marking a shift toward AI-orchestrated intrusions.

- Advertisement -

This was the first-known ransomware operation run end-to-end with large language model assistance, exploiting a Langflow flaw (CVE-2025-3248) to gain entry. Consequently, the attack harvested credentials, encrypted files, and dropped database tables, with a second strike using the ENCFORGE ransomware targeting AI infrastructure. Microsoft observed two compromised service principals—one for reconnaissance and another for destructive operations—executing over 300 read operations in 16 hours, then deleting more than 100 storage accounts in seven minutes. However, Azure resource locks and deletion protection blocked some attempts, demonstrating the value of independent safeguards. The initial breach stemmed from a publicly exposed client secret in a GitHub issue, which remained accessible through edit history. No ransom note or data exfiltration was confirmed, but the pattern suggests ransomware-aligned motives. “This activity highlights a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale,” Microsoft stated.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Sensex, Nifty crash over 1,000 points, hit May 2024 lows

India’s Sensex and Nifty crashed on Monday, with Sensex falling over 1,000 points and...

South Korea weighs crypto market-making after JPYC surge

South Korea's FSC is reviewing whether to introduce market-making for digital assets after JPYC...

Nvidia Gains as China Considers RTX 5500 GPU Purchases

Beijing is considering allowing select Chinese firms like ByteDance and Alibaba to buy NVIDIA’s...

Newsom Signs California Ban on Public Officials’ Memecoins

California Governor Gavin Newsom signed Assembly Bill 2409, barring state and local public officials...

Amazon stock could hit $1,000 by 2036, model says

CoinCodex's algorithmic model predicts Amazon stock could hit $1,000 by 2036, far above the...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading