Emergence of the JADEPUFFER Threat Actor: A New Age of AI-Driven Cyber Attacks
In a significant development in the realm of cyber threats, the notorious threat actor known as JADEPUFFER has been identified engaging in destructive operations within a Microsoft Azure environment, employing compromised service principals to execute their agenda. Microsoft, which has been diligently monitoring these activities under the designation Storm-3168, has acknowledged this as an alarming evolution in the tactics and methodologies employed by threat actors.
The attack occurred in early June 2026 and lasted approximately 18 hours, showcasing a calculated and extensive strategy. According to researchers Yossi Weizman, Tushar Mudi, and the Microsoft Security Research Team, the operations orchestrated by JADEPUFFER were made possible due to the breach of service principals, which led them to target a plethora of Azure resources, including Storage Accounts, SQL databases, Key Vaults, and Virtual Machines.
JADEPUFFER was first highlighted by Sysdig, which described it as the pioneering ransomware operation conducted end-to-end with assistance from a large language model (LLM). This intrusion took advantage of a known security vulnerability in Langflow, identified as CVE-2025-3248. Utilizing this exploit, JADEPUFFER harvested credentials, deepened its penetration into the network, and encrypted essential service configuration files. The operation culminated in the destruction of database tables and the issuance of a ransom note that mandated a payment in Bitcoin.
With the attack employing MySQL’s built-in AES_ENCRYPT() function for data encryption, it soon became evident that JADEPUFFER’s toolkit was versatile. After the initial breach, the threat actor targeted the same Langflow instance again but with a different strain of ransomware dubbed ENCFORGE. This malware was specifically engineered for AI infrastructure, adeptly scanning for an extensive array of file extensions—approximately 180—comprised of model checkpoints, vector databases, training datasets, and various macOS files.
Sysdig’s analysis posited that an autonomous agent was capable of reasoning about its targets, adeptly harvesting and reusing credentials. The agent’s ability to move laterally across networks, establish persistent access, and ultimately destroy databases made it a formidable adversary. Each technique employed, while not particularly novel or sophisticated on an individual level, was remarkably effective when combined by the AI model into a cohesive ransomware operation against inadequately protected internet-facing infrastructure.
During its investigation, Microsoft noted the involvement of two compromised service principals linked to the same tenant. The first was responsible for reconnaissance and resource discovery, while the second was tasked with the more destructive elements of the operation and additional credential collection.
The reconnaissance phase lasted nearly 16 hours, during which extensive enumeration activities were executed across Azure Virtual Machines, subscriptions, and resource groups. More than 300 read operations were logged during this period, demonstrating the thoroughness of JADEPUFFER’s reconnaissance efforts. Following this, the second service principal engaged in its operations approximately 90 minutes later, rapidly enumerating virtual machines and resource groups across two subscriptions.
What transpired next was a chaotic burst of destructive actions. Over the course of about seven minutes, the second service principal made over 100 attempts to delete storage accounts, targeting Azure Key Vaults, Function Apps, and multiple SQL databases. However, due to the use of an unsupported API version, numerous database deletion attempts were unsuccessful.
Despite the overall success of the attack—most targeted Azure Storage accounts were deleted—Microsoft highlighted the importance of independent safeguards such as Azure resource locks and storage account-level deletion protections. These measures proved effective in preventing complete devastation, even when a broad administrative access was held by a compromised identity.
Microsoft further revealed that the compromise of the service principal stemmed from a plain text exposure of its client ID, client secret, and tenant ID on a public GitHub issue, courtesy of an employee from the affected organization. After this sensitive information was removed, remnants remained accessible through the public edit history, underscoring the risks involved in managing credentials in contemporary cybersecurity environments.
The data gleaned from Microsoft’s investigations indicated that Storm-3168-linked infrastructure had also been conducting recurring probing against various Azure App services for multiple clients. This pattern of attacks strongly implies a degree of automation or scripting at play, given the organized structure of operations and the specific allocation of tasks to multiple service principals.
The overarching goal of these malicious actions appears to align with ransomware objectives, primarily aimed at crippling the victims’ ability to recover from the assault. Notably, no ransom note or explicit data exfiltration has been recorded in connection with the incident, raising further questions about the intent behind the attack.
Microsoft’s conclusion reflects a concerning shift toward AI-oriented attacks, highlighting the capacity of threat actors to coordinate intricate operations swiftly and at scale within cloud environments. In response to these emerging challenges, security teams must adapt by harnessing AI tools to enhance their strategies for detection, investigation, and remediation in ever-expanding digital landscapes.

