Storm-3168: Agentic-driven cloud attacks using compromised service principals

Executive Summary

Microsoft reports that the Storm-3168 threat actor, linked to JADEPUFFER, performed Azure reconnaissance, deleted resources, and accessed credentials by compromising service principals. The post details the tactics, techniques, and procedures used and offers defenders guidance on detection and mitigation.


Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-25T15:35:08+00:00 - Category: threat-intel

Original Description: Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

"Skill to do comes of doing."

— Ralph Emerson
Source: Microsoft Security