JadePuffer ransomware group uses AI agents to attack Azure and destroy cloud resources

Started by Golden Crow, Today at 01:07 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: JadePuffer ransomware group uses AI agents to attack Azure and destroy cloud resources   Views(Read 42 times)
Active members in this topic:
Golden Crow(1)

Golden Crow

BleepingComputer reports that Microsoft has uncovered attacks on Azure cloud environments carried out with the help of AI agents. The group behind them uses JadePuffer ransomware and is tracked by Microsoft as Storm-3168. Microsoft's security team found two attacks in June, and cloud security firm Sysdig had already written about JadePuffer's emergence in July. This looks like one of the clearest real world examples yet of criminals using agentic AI

The attackers got in using two compromised service principals, the security identities that let applications and automated tools log in to Azure. The credentials for one of them had appeared in a public GitHub issue before the attack, which was probably how they got in. AI agents then automated much of the attack, from reconnaissance and stealing credentials to moving through systems, setting up persistence and encrypting data

The destructive phase lasted just seven minutes. In that time, the attackers targeted more than 100 storage accounts plus Key Vaults, Function Apps, virtual machines and App Services. They made over 30 requests for storage account keys, most of which succeeded, and removed backup recovery protections to make restoration harder. An attempt to delete Azure SQL databases failed only because the tools used unsupported API versions

Some damage was prevented by Azure resource locks and storage account protections that the victims had in place. Microsoft recommends turning on cloud workload protection, scanning public repositories for leaked secrets and checking permissions against the principle of least privilege. Those are basics, but the speed of this attack shows why they matter so much

This lands in a month full of stories about AI agents going wrong, but this time it is not an accident. Seven minutes to wreck a cloud environment is terrifying. Are security teams ready for attacks that move this fast? And does anyone still leave credentials lying around on GitHub?


Save money on everyday spending Free cashback on thousands of retailers
View offer