JADEPUFFER hits Azure: 150 destructive operations in 35 minutes, one plaintext secret on GitHub
> TL;DR: In June 2026, the activity Microsoft tracks as Storm-3168 compromised two Azure service principals in the same tenant. The first explored for about 16 hours (300+ read operations). The second executed 150+ destructive or credential-collection operations in 35 minutes, including a 7-minute sequence with 100+ storage account deletion attempts. Root cause: client ID, client secret and tenant ID in plaintext in a public GitHub issue.
Two service principals, two roles
The timeline documented by Microsoft Security Research (Yossi Weizman, Tushar Mudi) is strikingly legible:
This is not ransomware that encrypts and then asks. It is an actor that deletes — including resources tied to backups and recovery protection. The objective is consistent with ransomware logic, even though no ransom note was observed in this incident, and no exfiltration.
What held, what did not
The technical lesson: resource locks and deletion protection are classic Azure controls, often enabled by reflex. Here they made the difference between a loss and a catastrophe. They are not "AI" controls: they are configuration controls, and they worked.
The root cause: one plaintext secret on GitHub
The service principal's client ID, client secret and tenant ID were exposed in plaintext in a public GitHub issue. The issue was removed later — but the secrets remained visible in the repository's public edit history.
Deleting an issue does not delete git history. As long as the repository is public, every commit contains the secrets that passed through it. And a compromised service principal with tenant access is the equivalent of an Azure master key.
Repeated probing of Azure App Services was also observed from Storm-3168-related infrastructure — likely automated or scripted, as in most campaigns of this type.
The JADEPUFFER context
JADEPUFFER was first documented by Sysdig as the first ransomware operation run end-to-end with LLM help. The initial attack exploits CVE-2025-3248 in Langflow, harvests credentials, encrypts Nacos config files with MySQL AES_ENCRYPT(), drops database tables and leaves a Bitcoin ransom note.
The same Langflow instance was later hit by ENCFORGE, a Go-based ransomware targeting AI infrastructure: about 180 file extensions, model checkpoints, vector databases, training datasets, embedding indexes — down to macOS Keychains, Xcode projects, Pages and Numbers files.
The Storm-3168 incident documented by Microsoft shows the same group — or a group from the same cluster — operating with first-class Azure identities, with no LLM required in the loop. The LLM is an accelerator, not a prerequisite.
What to check right now
.env secrets.DELETE on storage accounts is such a strong signal it needs no machine learning. What it needs is someone to see it.The takeaway
150 operations in 35 minutes, including 100 deletions in 7 minutes: that is the speed of a script, not of a human. Detection will not win on speed — it wins on alerting to the action. A service principal deleting in bulk is the clearest signal an Azure environment can give. And it usually starts with a secret someone pasted somewhere.
Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Keycloak and CVE-2026-1180: why dynamic client registration deserves real review
In March 2026, Keycloak fixed a blind SSRF via jwks_uri in dynamic OIDC client registration. Here is why CVE-2026-1180 matters.
Oracle E-Business Suite CVE-2025-61882: Cl0p hits Michelin and 100+ companies in MOVEit's wake
The Cl0p group exploited a critical zero-day in Oracle E-Business Suite (CVE-2025-61882, CVSS 9.8) to run a mass data-extortion campaign. Michelin, Harvard, the Washington Post, Logitech, Cox Enterprises and more than 100 organizations worldwide were hit.
VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims
CVE-2026-59310 (CVSS 9.8), a path traversal flaw in VMware vCenter, has been exploited by a suspected China-nexus actor to deploy backdoors and a Babuk-derived ransomware. 361 compromised IPs across 47 countries, including 25 in France.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant ActionShield audits.