Microsoft details Storm-3168 agentic cloud attacks: 100+ storage deletions in 7 minutes

yuridiogenes · x · 2026-09-26

Microsoft Security Research published new findings on Storm-3168 (JADEPUFFER), an evolution of what Sysdig identified in July 2026 as the first documented agentic ransomware operation. Attackers used two compromised service principals with divided roles — discovery, destruction, and credential collection — with timing and overlapping token streams strongly indicating scripted execution, including 100+ storage account deletion attempts in about seven minutes. Collected cloud credentials could facilitate future exfiltration.

Original post →

More from Safety

Safety channel →