HomeCyber BalkansStorm-3168 Hackers Exploit Compromised Service Principals to Wreck Azure Cloud Resources

Storm-3168 Hackers Exploit Compromised Service Principals to Wreck Azure Cloud Resources

Published on

spot_img

Microsoft Discovers Destructive Azure Campaign Linked to Storm-3168

Microsoft recently unearthed a significant and destructive cyber campaign connected to a group known as Storm-3168, alternatively referred to as JADEPUFFER. This illicit operation involved the manipulation of compromised service principals, enabling attackers to conduct extensive reconnaissance, delete crucial resources, undermine recovery mechanisms, and access sensitive credentials linked to storage accounts.

In its investigation, Microsoft underscored a critical vulnerability in cloud security: one improperly secured workload identity has the potential to empower attackers with necessary automation and permissions, facilitating rapid and extensive disruption across cloud environments. This incident serves as a stark reminder of the implications of inadequate security measures in cloud computing.

Storm-3168 utilized two compromised service principals from a single Azure tenant, illustrating a coordinated attack strategy. The primary service principal embarked on an extensive reconnaissance mission that lasted approximately 15 hours and 30 minutes. Within this timeframe, it successfully executed more than 300 read operations, allowing the attackers to catalogue a comprehensive inventory of the victim’s Azure resources—ranging from virtual machines, subscriptions, and resource groups to other essential assets.

A secondary service principal conducted a markedly rapid survey, scanning two Azure subscriptions and identifying various virtual machines and resource groups in a mere five seconds. Approximately 16 hours after this fast reconnaissance phase, it turned its attention to the Azure App Service configuration stores, presumably to uncover any exposed application secrets.

At that point, the operation transitioned almost instantaneously from reconnaissance to resource harm. Less than one second following a failed attempt to list keys from a non-existent storage account, the second service principal initiated a series of destructive actions that unfolded over a span of seven minutes. During this critical window, the attacker attempted over 150 destructive or credential-collection actions, which included more than 100 deletion attempts targeting Azure Storage accounts. Microsoft’s reports highlighted that many of these targeted storage accounts were successfully eliminated.

Additionally, the attackers successfully deleted an Azure Key Vault, Function App, and App Service Plan belonging to the same resource group. While they attempted to delete Azure SQL databases concurrently, these attempts were thwarted due to the use of an unsupported API version. This indicates a level of operational complexity that underscores the attackers’ commitment to dismantling the victim’s cloud infrastructure.

Intriguingly, the attackers demonstrated a clear strategy aimed at diminishing the victim’s disaster recovery capabilities. They made attempts to remove Azure Site Recovery locks and Azure Backup protection locks, suggesting a clear intent to compromise the victim’s ability to restore vital data and services post-attack. Despite their expansive permissions, some deletion attempts were blocked due to Azure resource locks and storage account-level deletion protection still being effective, emphasizing the necessity for independent recovery controls that cannot easily be compromised.

Approximately 30 minutes after the last destructive act, Storm-3168 resumed its activities by seeking a comprehensive inventory of storage accounts. This phase involved successful issuance of over 30 ListKeys requests that retrieved storage account access keys, including those tied to Azure Site Recovery resources. Such access could potentially expose sensitive cloud data and facilitate further information collection or exfiltration efforts.

Though Microsoft did not observe any ransom notes or confirm instances of data theft, they noted that the combination of destruction, impairment of recovery options, and credential collection appeared consistent with tactics associated with ransomware or extortion operations. This identification aligns with broader trends in cybercrime, particularly as malicious actors increasingly interlink destructive techniques with credential-stealing strategies to amplify their leverage over victims.

Microsoft further evaluated that the campaign exhibited automated or agent-driven characteristics due to the efficiency of its execution, the strategic division of tasks, and the synchronized usage of overlapping tokens across operations. Two deletion-capable tokens operated in tandem for approximately 70 seconds, enabling the attackers to simultaneously target both Storage and SQL resources.

The method of initial compromise remains elusive; however, Microsoft’s investigation surfaced the tenant ID, client ID, and client secret, which had previously been exposed in plaintext in a public GitHub issue. Even after the issue was revised, the secret persisted in the public edit history, highlighting the vulnerability that public exposure can create for organizational security.

In light of these findings, Microsoft urges organizations to act promptly by revoking and rotating any exposed credentials, enforcing least-privilege Azure Role-Based Access Control (RBAC) permissions, fortifying backup resources with independent protections, and actively monitoring for unusual Azure Resource Manager operations and bulk ListKeys requests. These measures are vital to safeguarding cloud environments and mitigating the risks associated with such cyber threats.

By disseminating these findings, Microsoft aims to bolster awareness within the industry, prompting companies to strengthen their cloud security protocols in an ever-evolving threat landscape.

Source link

Latest articles

MemTensor npm/PyPI Packages Compromised – CyberMaterial

Supply Chain Attack Compromises MemOS Framework: A Deep Dive into the Incident In a significant...

Ransomware Gangs Taking Advantage of Serious TeamCity Vulnerability

Alert Issued by CISA on Ransomware Exploiting JetBrains TeamCity Vulnerability On Wednesday, the U.S. Cybersecurity...

Local AI Model Bypasses EDR to Dump Windows LSASS Credentials Uncensored

A recent demonstration reveals a significant advancement in the realm of cybersecurity, showcasing how...

Party Invite Phishing Scams Aim at Users

Wave of Phishing Attacks Using Fake Party Invitations In a rising trend of cybercrime, a...

More like this

MemTensor npm/PyPI Packages Compromised – CyberMaterial

Supply Chain Attack Compromises MemOS Framework: A Deep Dive into the Incident In a significant...

Ransomware Gangs Taking Advantage of Serious TeamCity Vulnerability

Alert Issued by CISA on Ransomware Exploiting JetBrains TeamCity Vulnerability On Wednesday, the U.S. Cybersecurity...

Local AI Model Bypasses EDR to Dump Windows LSASS Credentials Uncensored

A recent demonstration reveals a significant advancement in the realm of cybersecurity, showcasing how...