Published on September 29, 2026

Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack


Severity

High

Detail

Microsoft has disclosed a destructive cloud attack conducted by a threat actor tracked as Storm-3168, which leveraged compromised Azure service principal credentials to rapidly delete cloud resources and target recovery mechanisms within a victim environment.

The attack demonstrates how compromised cloud identities can provide attackers with extensive control over Azure environments, enabling them to enumerate resources, disrupt services, access storage account keys, and interfere with recovery operations. Microsoft linked the activity to previous JADEPUFFER ransomware-related operations, although the investigation did not confirm data exfiltration or ransom demands in this specific incident.

Researchers identified two compromised service principals operating within the affected Azure tenant. One identity focused on reconnaissance and environment mapping, while the second conducted destructive actions and attempted to obtain storage account access keys.

How?

The attack began with the compromise of Azure service principal credentials. Microsoft noted that one service principal’s client ID, tenant ID, and secret had previously appeared in plain text within a public GitHub issue, although investigators were unable to definitively confirm that this exposure was the initial access vector.

In early June 2026, the first compromised service principal spent approximately 15 hours performing reconnaissance activities, including more than 300 successful read operations against Azure resources. The attacker enumerated subscriptions, virtual machines, resource groups, storage resources, and other cloud assets.

A second compromised service principal subsequently conducted additional discovery operations across multiple subscriptions and examined App Service configurations, potentially searching for sensitive credentials or configuration data. Less than two minutes after its final reconnaissance activity, the attacker initiated a destructive phase. Within approximately seven minutes, the threat actor attempted more than 100 storage account deletions, successfully removing most targeted resources.

The attacker also deleted Azure resources including Azure Storage Accounts, Azure Key Vaults Azure Function Apps and Azure App Service Plans. Several deletion attempts were prevented due to resource locks and account-level deletion protection, demonstrating the effectiveness of independent Azure security safeguards.

Storm-3168 additionally attempted to delete Azure SQL Databases and interfere with Azure Site Recovery and Azure Backup protections. While SQL database deletion attempts failed because of an unsupported API version, the activity indicates a deliberate effort to disrupt recovery capabilities and hinder restoration efforts.

Approximately 30 minutes after the destructive activity concluded, the compromised identity performed more than 30 successful ListKeys operations against Azure Storage Accounts, including recovery-related storage resources. Access to storage account keys could potentially enable future access to sensitive data or facilitate follow-on attacks against backup infrastructures.

Microsoft observed multiple active authentication tokens being used simultaneously, suggesting coordinated or automated execution of malicious operations.

Indicator of Compromises (IoCs)

The table below shows list of IoCs associated with Storm-3168 activity.

TypeIndicatorDescription
IPv445.131.66[.]106App Service probing and malicious Azure Resource Manager requests
IPv434.153.223[.]102App Service probing activity
IPv464.20.53[.]230App Service probing activity

Conclusion

The Storm-3168 campaign demonstrates how compromised cloud identities can be leveraged to rapidly disrupt Azure environments without requiring exploitation of platform vulnerabilities. By abusing privileged service principal credentials, the threat actor was able to enumerate resources, delete critical cloud services, target recovery mechanisms, and collect storage account access keys within a matter of minutes.

The attack highlights the importance of protecting service principal credentials, enforcing least-privilege access, implementing resource locks, and restricting access to backup and recovery infrastructure. Organizations should continuously monitor unusual resource enumeration, large-scale deletion attempts, excessive key retrieval activity, and unauthorized changes to recovery protections. Regular credential rotation, secret scanning, and reviews of service principal permissions can significantly reduce the risk of similar attacks.

Source

https://cybersecuritynews.com/storm-3168/