An attacker known as JADEPUFFER spent roughly 18 hours inside a Microsoft Azure environment in early June, then destroyed most of it in 35 minutes. Microsoft’s security research team, tracking the group as Storm-3168, published its account on September 25.

The entry point was a service principal credential posted, in plaintext, inside a public GitHub issue. Someone later edited the issue to remove the secret, but GitHub retains edit history, and the credential stayed retrievable there. Two compromised service principals spent 16 hours quietly enumerating Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, and virtual machines across two subscriptions, more than 300 successful read operations without triggering a response. Then, 70 seconds after the last reconnaissance call, the attacker pivoted to destruction: over 100 attempts to delete storage accounts in seven minutes, most successful, followed by a Key Vault, a Function App, and an App Service plan deleted outright. Credential harvesting followed the destruction, not the other way around, evidence the attack was scripted well enough to loot on the way out.

Why it matters: the attack worked entirely on a leaked secret and standard Azure Resource Manager permissions. No CVE, no zero-day, no novel technique. Microsoft’s guidance is blunt: “credentials exposed in any public internet location should be treated as compromised and promptly revoked or rotated,” regardless of whether the exposure was later edited out. Editing a GitHub issue does not invalidate a secret that was ever visible in its history.

The original insight is sequencing, not access. Most cloud incident response runbooks are built to catch lateral movement, the slow crawl from one resource to the next. JADEPUFFER inverted that: 16 hours of quiet, permission-scoped reads that look like normal automation, then a destructive burst too fast to intervene in. A detection strategy tuned to catch unusual movement will miss this, because nothing about the reconnaissance looks unusual until the destruction is already finished.

Prior CyberTech coverage: Wiz’s AI Agent Found a Snowflake Flaw Copilot Missed and A Cloudflare Bug Let Tenants Read Each Other’s Disk.

Source: Microsoft Security Blog