Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft describes JADEPUFFER-linked cloud activity associated with Storm-3168, involving Azure reconnaissance, resource deletion, and credential access through compromised service principals. The post provides guidance for defenders confronting the activity.
1 sourcePublished Updated
Why it matters
The activity involves compromised service principals and deletion of Azure resources, making the account-access and cloud-defense implications significant for security teams.