CyberSecurity SEE

Hackers Exploit Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials

Hackers Exploit Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials

Microsoft has recently disclosed details about a destructive cyber campaign focused on its Azure cloud platform, linked to a threat actor known as JADEPUFFER, which the company tracks as Storm-3168. This situation comes as cloud security remains a top concern for many organizations, highlighting the vulnerabilities associated with compromised service principals.

The threat actors employed compromised service principals to navigate and exploit cloud resources, leading to data and operational degradation. Their tactics included not only the deletion of Azure Storage accounts and various application components but also attacks aimed at recovery controls. Additionally, they aimed to collect access keys for storage accounts, which could enable future data breaches and theft.

This revelation adds crucial context to prior research conducted by Sysdig, which had first identified JADEPUFFER in July 2026, recognizing it as the first documented agentic ransomware operation. As such, this latest campaign revises and confirms the threat landscape posed by this group, demonstrating a sophisticated understanding of cloud infrastructure.

In Microsoft’s findings, two compromised service principals were detected within a shared Azure tenant. The activities of the first identity diverged significantly from those of the second. The first service principal executed over 300 successful read operations within a span of approximately 15 hours and 30 minutes. This reconnaissance operation involved enumerating virtual machines, subscriptions, resource groups, and additional Azure resources, thereby granting the operators a comprehensive view of the victim’s cloud assets.

Roughly 90 minutes after the reconnaissance activities, the second compromised identity performed rapid enumeration of virtual machines and resource groups across two subscriptions, completing this operation in just five seconds. Both identities utilized infrastructure associated with Storm-3168 and presented matching network fingerprints while employing the same user agent, python-requests/2.34.2. This raises concerns about the coordinated nature of their activities.

The destructive actions escalated promptly; after querying Azure App Service configuration stores—presumably searching for exposed secrets—the second service principal engaged in a series of destructive commands shortly after a failed ListKey request against a nonexistent storage account. Within 35 minutes, it executed more than 150 operations aimed at deletion or credential collection. Among these actions were over 100 attempts to delete Azure Storage accounts, resulting in the successful removal of the majority of targeted accounts.

However, Microsoft noted that certain deletions were thwarted by Azure resource locks and storage account deletion protection. These protections serve as a crucial safety net, indicating the importance of recovery safeguards, even when attackers gain access to highly privileged identities.

During its operation, Storm-3168 not only deleted an Azure Key Vault and several application components but also attempted to erase multiple Azure SQL databases. The failed attempts at database deletions were attributed to the use of an unsupported API version rather than a lack of permission. This further underscores a critical point: compromised service principals can wield extensive powers and capabilities, making them an attractive target for cybercriminals.

In a sign of intentional targeting, the campaign also saw attempts to weaken recovery systems by attempting to eradicate Azure Site Recovery locks and Azure Backup protection locks. Such actions are consistent with the strategies employed by ransomware operators, who often seek to disrupt a victim’s operational capabilities and diminish their chances of data restoration.

Approximately 30 minutes after completing its destructive operations, the compromised service principal made subsequent Azure Storage inventory requests, successfully executing over 30 ListKeys operations. Such requests aimed to obtain storage account access keys, which are vital for accessing sensitive cloud data and services, thereby amplifying the risk of data exfiltration.

While Microsoft did not confirm any successful data theft or the presence of a ransom note, the combination of cloud resource deletion and credential collection aligns closely with common ransomware and extortion objectives. Investigators could not definitively determine the initial access vector; however, they uncovered a concerning incident where one service principal’s client ID, client secret, and tenant ID had been exposed in plaintext within a public GitHub issue, revealing lapses in security protocol.

Furthermore, Microsoft shared insights on the growing threat posed by workload identities, arguing that organizations must adopt more stringent measures. Recommendations included minimizing service principal permissions, regularly scanning for exposed secrets, and closely monitoring Azure Resource Manager activities for anomalies.

Microsoft emphasized the urgency in addressing these vulnerabilities, suggesting the implementation of relevant Defender for Cloud protections. Moreover, security teams are encouraged to secure backup systems independently, impose resource locks, and maintain vigilance against attempts to destabilize recovery protections.

As adversaries leverage automation and increasingly sophisticated methods to compromise cloud infrastructures, such as utilizing AI-enhanced workflows, Microsoft highlighted the necessity for defenders to adopt equally automated and comprehensive responses. As an illustration of this commitment, Microsoft referenced Project Perception and Defender for AI Security, initiatives designed to bolster detection, investigation, and containment of threats in multifaceted cloud environments.

As organizations navigate the complexities of cloud security, Microsoft’s findings stand as a critical reminder of the evolving threat landscape and the need for vigilant, proactive defenses against increasingly advanced cyber threats.

Source link

Exit mobile version