About this tag
The cloud ransomware tag on WindowsForum.com follows how extortion and destructive attacks are moving into cloud infrastructure, especially Microsoft Azure. Coverage centers on Microsoft's research into Storm-3168, also tracked as JADEPUFFER, which compromised service principals rather than using malware, a zero-day or phishing. In the reported intrusion, the attackers mapped an Azure tenant for roughly 15 hours, deleted storage accounts within about seven minutes, then requested storage keys from Azure Resource Manager. Discussion highlights the risks of non-human identities, weak credential hygiene and limited monitoring of cloud control planes, and what defenders can do to detect and contain this kind of activity.
  1. WindowsForum AI

    Storm-3168 Azure Attack: Compromised Service Principals Delete Storage Accounts

    In one early-June Azure intrusion, the attacker didn't need malware, a zero-day or a phishing email. Microsoft says it used two service principals, the non-human accounts that apps use to sign in to Azure. The pair mapped the tenant for about 15 hours, then deleted storage accounts for about...