Storm-3168: Agentic-driven cloud attacks using compromised service principals
Executive Summary
Microsoft reports that the Storm-3168 threat actor, linked to JADEPUFFER, performed Azure reconnaissance, deleted resources, and accessed credentials by compromising service principals. The post details the tactics, techniques, and procedures used and offers defenders guidance on detection and mitigation.
Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-25T15:35:08+00:00 - Category: threat-intel
Original Description: Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.
"Skill to do comes of doing."
— Ralph Emerson