← All posts / Meta

Seven Minutes to Delete a Cloud: Microsoft Exposes JadePuffer, the First Agentic Ransomware Crew

Microsoft documents Storm-3168/JadePuffer wiping 100+ Azure Storage accounts with LLM-driven automation — ransomware that no longer has a human at the keyboard.

Seven Minutes to Delete a Cloud: Microsoft Exposes JadePuffer, the First Agentic Ransomware Crew

Ransomware has always had a human at the keyboard — or at minimum, a human writing the scripts that run the keyboard. That assumption quietly expired this year. In a detailed technical report published September 25, Microsoft Security Research documented Azure-focused attacks by the actor it tracks as Storm-3168, better known as JadePuffer: what Sysdig in July assessed as the first documented agentic ransomware operation, an extortion campaign driven end-to-end by a large language model rather than a human operator.

The numbers Microsoft extracted from the victim tenant’s logs read like a stress test of everything wrong with cloud identity hygiene. In one attack, the destructive stage lasted approximately seven minutes, during which the actor attempted more than 100 storage account deletions — most of them successful. Over a 35-minute window, a single compromised service principal ran over 150 destructive or credential-collection operations, taking out an Azure Key Vault, a Function App, and an App Service plan alongside the storage wipe, while attempting parallel deletions of Azure SQL databases and hammering at Site Recovery and Azure Backup protection locks designed to keep recovery possible.

The anatomy of the attack

Microsoft observed two compromised service principals belonging to the same tenant, with a clear division of labor that itself hints at automation. The first performed reconnaissance: enumerating Azure Virtual Machines, subscriptions, resource groups, and resources for roughly 15.5 hours across more than 300 successful read operations, building a complete map of the organization’s environment. About 90 minutes after that enumeration began, the second service principal enumerated VMs and resource groups across two subscriptions — in five seconds. Both identities used Storm-3168-linked infrastructure, the same network fingerprint, and the user agent python-requests/2.34.2.

The timing is what gives the game away. Sixteen hours after the initial inventory, the second principal enumerated App Service configuration stores, possibly hunting for exposed credentials. Seventy seconds after that final inventory operation, destruction began — less than one second after an unsuccessful ListKey call against a nonexistent storage account. Microsoft’s verdict: the interval patterns and overlapping token streams “strongly indicate automated or scripted execution,” with five unique tokens issued to one identity, four supporting deletions running concurrently in a 70-second window, one token focusing purely on storage deletion while another mixed storage and SQL deletion. This is orchestration, not an attacker clicking through a portal.

The initial access vector is depressingly familiar. The impacted service principal’s client ID, client secret, and tenant ID had been posted in plaintext in a public GitHub issue by an employee of the victim organization. The issue was later edited to remove the secret — but the secret remained retrievable through the issue’s public edit history. Microsoft emphasizes a point too many teams still miss: removing or redacting an exposed secret does not invalidate it. Credentials exposed anywhere public should be treated as compromised and rotated.

From CVE to extortion playbook

JadePuffer was first documented by the Sysdig Threat Research Team on July 1, and the original case is worth revisiting because it shows just how alien agentic malware behaves. Initial access came through CVE-2025-3248, a missing-authentication flaw in the code-validation endpoint of Langflow, the open-source framework for building LLM applications. From there, the LLM ran an adaptive, fully automated campaign: enumerating the host, sweeping the environment in parallel for LLM provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials with explicit coverage of both Chinese providers like Alibaba, Tencent, and Huawei and Western ones like AWS, GCP, and Azure, crypto wallet seed phrases, and database configuration files. It dumped Langflow’s backing Postgres database, staged the loot, reviewed it, and deleted the staging files. It pivoted through internal networks, found a MinIO object store running on default credentials, and worked through its full enumeration playbook — prioritizing a terraform-state bucket, the Crown Jewels of any infrastructure.

What stunned researchers was the payload’s texture. JadePuffer’s code was self-narrating, full of natural-language reasoning, target prioritization, and detailed annotations of the kind LLMs produce reflexively and human operators rarely bother writing. And it adapted in real time: in one sequence, it went from a failed database login to a working fix in 31 seconds, retrying failed steps within refined parameters. Microsoft’s new report shows the same actor has since graduated to bulk cloud resource destruction at ARM scale, harvesting 30+ storage account access keys — including accounts tied to Azure Site Recovery — for what could facilitate future exfiltration.

Why defenses partially held

Amid the wreckage there is one genuinely encouraging finding. A handful of storage accounts survived the deletion spree — not because the attacker lacked permissions, but because Azure resource locks and storage account-level deletion protection blocked the attempts. Microsoft frames this as “the value of independent safeguards that remain effective even when a compromised identity has broad administrative permissions.” The SQL databases also survived, though only by accident: the actor used an unsupported API version for the Azure SQL resource type, and every deletion failed.

The lesson is layered defense in the most literal sense. Assume the credential is already leaked — because it probably is, on some GitHub issue’s edit history or in some CI log. What matters is whether a single compromised workload identity can enumerate everything, delete everything, and defeat the recovery mechanisms on its way out.

The agentic era cuts both ways

Microsoft explicitly ties the findings to a broader shift toward AI-orchestrated attacks, where threat actors coordinate complex post-compromise operations across cloud environments with greater speed and scale than human crews can match — and explicitly argues that defenders must respond in kind, pointing to Project Perception and MDASH as efforts to let security teams investigate and respond across sprawling environments with AI rather than having analysts manually trace each individual action. The company also published MITRE ATT&CK mappings for the campaign spanning exploit public-facing application (T1190), valid cloud accounts (T1078.004), cloud service discovery (T1526), data destruction (T1485), and inhibit system recovery (T1490), plus indicators of compromise including three IPv4 addresses used for App Service probing.

For security teams, the checklist writes itself: treat every publicly exposed service principal secret as burned and rotate it; enforce least privilege on workload identities; protect the recovery plane — Site Recovery and Backup locks — as fiercely as production; and enable deletion protections that operate independently of role-based access control. For everyone else, JadePuffer is the marker of a transition. When the average breach dwell time is shrinking because the attacker doesn’t need sleep, and a 31-second fix loop counts as patience, the economics of both extortion and defense have changed. The first agentic ransomware crew isn’t a proof of concept anymore. It has a cloud practice, and it works in seven-minute bursts.