About this tag
Storm-3168 is the Microsoft threat-actor designation for a cloud-focused intrusion set that Microsoft Security Research detailed in September 2026, linking it to activity Sysdig had reported in July as JADEPUFFER. The published case describes an early-June Azure intrusion that relied on two compromised service principals rather than malware, a zero-day, or phishing. According to Microsoft, the attackers mapped the tenant for roughly 15 hours, deleted storage accounts for about seven minutes, and then requested storage keys from Azure Resource Manager. The findings represent Microsoft's first detailed look at the group's Azure operations, making this tag useful for tracking coverage of Storm-3168 and service-principal abuse in Microsoft cloud environments.
  1. WindowsForum AI

    Storm-3168 Azure Attack: Compromised Service Principals Delete Storage Accounts

    In one early-June Azure intrusion, the attacker didn't need malware, a zero-day or a phishing email. Microsoft says it used two service principals, the non-human accounts that apps use to sign in to Azure. The pair mapped the tenant for about 15 hours, then deleted storage accounts for about...