Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
探索我们的品牌
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
广告
新闻通讯注册
网络安全主题
全球
边缘计算
DR Technology
活动
资源
云安全
威胁情报
漏洞与威胁
网络攻击与数据泄露
新闻
JadePuffer AI 攻击者在一场破坏性云攻击中攻陷了 Azure 租户
这位“代理型威胁行为者”可能利用暴露的凭据访问资源,并删除了基于云的存储、应用程序和数据库。
Elizabeth Montalbano,特约撰稿人
2026年9月28日
4分钟阅读
来源:BOY WWIRAT 通过 GETTY IMAGES 提供
一名代理型 AI 攻击者将攻陷的 Microsoft Azure 凭据转化为武器,在几分钟内摧毁云资源,这看起来像是一场勒索软件或敲诈攻击。
微软将该攻击归咎于 JadePuffer,并将其追踪为 Storm-3168。Sysdig 研究人员在7月确认该组织为首个有据可查的大语言模型(LLM)驱动的勒索软件行动。
根据9月25日发布的 Microsoft Security Research 博客文章,JadePuffer 在此案中攻陷了两个合法的服务主体(service principals),随后花费数小时绘制受害者环境的地图。在进行侦察后,攻击者发起了一场高度自动化的破坏活动,试图清除存储、应用程序和数据库,同时针对备份和恢复控制措施。
微软表示,整体活动符合支持勒索软件和敲诈行动的策略。“然而,我们未在此处描述的活动观察到勒索信,也未确认数据成功外泄,”该文章由 Microsoft Security Research 及研究人员 Yossi Weizman 和 Tushar Mudi 署名。
相关:如何为现代网络安全构建 SASE 框架
先侦察,后破坏
微软详细描述了6月初发生的攻击,JadePuffer 攻陷了属于同一 Azure 租户的两个服务主体。其中一个负责侦察和资源发现;另一个处理发现、破坏性操作和凭据收集。
第一个被攻陷的服务主体花费了约15.5小时来映射虚拟机(VM)、订阅、资源组和其他资源,同时执行了超过300次成功的读取操作。在侦察开始约90分钟后,第二个服务主体在短短五秒内枚举了两个订阅中的 VM 和资源组。
“Weizman 和 Mudi 写道:‘这种广泛的活动将使威胁行为者能够全面了解组织内的 Azure 环境。’”
16小时后,第二个服务主体成功枚举了 Azure App Service 配置存储,可能是在寻找暴露的凭据,并尝试查找 Azure OpenSearch 资源但未成功。该服务主体还尝试对不存在的存储账户执行 ListKey 操作。
不到一秒后,破坏性活动开始,其中包括超过100次删除存储账户的尝试,其中大多数成功了。JadePuffer 还删除了同一资源组中的 Azure Key Vault、Function App 和 App Service plan。同一个服务主体还尝试并行删除多个 Azure SQL 数据库,但由于攻击者使用了不受支持的 API 版本,这些尝试失败了。
相关:SASE 将网络与安全融合为单一云解决方案
在破坏性活动开始后约30分钟,该服务主体对 Azure Storage 账户(包括与 Site Recovery 相关的账户)发出了清单请求,随后又发起了超过30次成功的 ListKeys 请求以检索其访问密钥。
GitHub 中的暴露机密
微软无法确定攻击者最初是如何攻破服务主体的,但发现受影响组织的一名员工曾在公开的 GitHub 问题中明文泄露了该服务主体的客户端 ID、客户端密钥和租户 ID。该问题后来经过编辑以移除泄露的密钥,但相关信息仍可通过其公开的历史版本访问。微软无法确认泄露的凭据是否在攻击中被使用。
尽管如此,Corsica Technologies 首席信息安全官 Ross Filipek 指出,“承认凭据泄露可能是一个因素,这发出了一个有用的警告,即常规清理可能会使账户暴露。”“一旦攻击者掌握了应用程序身份,他们的活动看起来就像普通的云管理一样。”
相关报道:无声的“TwinLoot”网络威胁完全在微软云端运作
微软表示,此次攻击将已知的 JadePuffer 活动扩展到了 Azure 领域,并凸显了由 AI 协调的攻击以“更快的速度和规模”协调跨云环境的复杂后续操作的可能性。
然而,一位专家并不确信这次攻击是完全由 AI 主导的,就像 JadePuffer 之前的活动那样。“我同意微软关于 AI 协调攻击的警告,但 Azure 的证据显示的是协调一致的自动化,而非证明 AI 指导了每一步,”Swimlane 首席安全自动化架构师 Nick Tausek 说。
不过,他承认代理式 AI 仍然可能成为危险的对手。
事实上,微软表示,自今年年初以来,与 JadePuffer 相关的基础设施一直在探测不同客户 across 多个 Azure App 服务。根据博文内容,该代理似乎正在测试各种渗透云环境的方法,包括通过“WordPress 管理、PHP-CGI、LangFlow 的代码验证端点 (/api/v1/validate/code) 以及其他类似 Web Shell 的路径”。
保护 Azure 环境免受 JadePuffer 侵害
确实,随着代理式 AI 攻击者能力的演变——自主 AI 攻击变得日益普遍,甚至达到令人恐惧的程度——防御者必须做出相应回应,同样利用 AI 来缓解威胁,微软建议道。
研究人员写道:“与其要求分析师手动跟踪每一个单独的操作,Project Perception 和 MDASH 等举措旨在支持一种模型,使防御者能够使用 AI 在越来越大且复杂的环境中进行调查和响应。”
微软还在其博文中推荐了各种缓解措施,以降低与 JadePuffer 类似活动的风险和影响。这些建议包括:为关键的 Azure 工作负载启用适当的 Microsoft Defender for Cloud 计划;保护和持续评估应用程序凭据和密钥;立即轮换受损或泄露的凭据并建立凭据生命周期实践;以及将最小权限原则应用于服务主体和其他工作负载身份,以及其他缓解措施。
关于作者
伊丽莎白·蒙塔巴诺 (Elizabeth Montalbano)
特约撰稿人
伊丽莎白·蒙塔巴诺是一位自由撰稿人、编辑和记者,拥有 30 年的专业经验,并持有亚利桑那州立大学的硕士学位。她的专业领域包括企业技术、网络安全、商业和文化。在漫长的职业生涯中,伊丽莎白曾在凤凰城、旧金山和纽约市担任全职记者。她专注于新闻报道和分析,利用多年的经验以批判性的眼光审视网络安全的现状。她目前居住在葡萄牙西南海岸的一个村庄,在空闲时间,她喜欢冲浪、与狗一起徒步旅行、种植植物,以及作为歌手和音乐家进行表演和演出。
想在您的 Google 搜索结果中看到更多 Dark Reading 的报道吗?
立即添加我们
更多见解
行业报告
云安全现状:最新挑战
组织如何应对事件响应
企业如何开发安全应用
RSAC 2026 内幕:安全领袖揭示重塑您防御策略的风险
Black Hat USA 2025 的重要新闻与见解
获取更多研究
网络研讨会
有效的警报分类:减少噪音并发现真实威胁
2027 年网络安全展望
威胁暴露分析:衡量和传达安全风险
基准分数是虚假信号
构建高效的红队:超越渗透测试
更多网络研讨会
您可能还喜欢
云安全
单一攻击者利用 AI 在 72 小时内突破 AWS 云环境
作者:Alexander Culafi
2026 年 7 月 8 日
云安全
CSA:CISO 应准备应对后 Myths 漏洞风暴
作者:Alexander Culafi
2026 年 4 月 13 日
云安全
APT41 投递“零检测”后门以窃取云凭据
作者:Elizabeth Montalbano
2026 年 4 月 13 日
云安全
TeamPCP 将云基础设施转化为犯罪机器人
作者:Jai Vijayan
2026 年 2 月 9 日
精选
查看 Black Hat USA 2026 大会指南,获取来自该大会及关于该大会的报道和情报!
编辑精选
应用安全
“Salesbleed”利用 Salesforce 代理实现 Slack 网络钓鱼
作者:Nate Nelson
2026 年 9 月 24 日
6 分钟阅读
网络攻击与数据泄露
定义 2026 年夏天的三大网络威胁
作者:Arielle Waldman
2026 年 9 月 24 日
应用安全
提示注入漏洞击中价值 40 亿美元的代理 AI 应用“Manus”
作者:Nate Nelson
2026 年 9 月 24 日
5 分钟阅读
2026 年 10 月 8 日 | 虚拟会议
为企业构建安全的 AI 战略
领先应对 AI 风险
想在您的 Google 搜索结果中看到更多 Dark Reading 的报道吗?
紧跟最新的网络安全威胁、新发现的漏洞、数据泄露信息和新兴趋势。每日或每周直接发送至您的电子邮件收件箱。
订阅
发现更多
Black Hat
Omdia
与我们合作
关于我们
认识编辑团队
广告合作
reprint 服务
加入我们
新闻通讯注册
关注我们
版权所有 © 2026 TechTarget, Inc. d/b/a Informa TechTarget。本网站由 Informa TechTarget 拥有并运营,它是全球网络的一部分,旨在告知、影响并连接全球的科技买家和卖家。所有版权均归其所有。Informa PLC 的注册地址为 5 Howick Place, London SW1P 1WG。在英格兰和威尔士注册。TechTarget, Inc. 的注册地址为 275 Grove St. Newton, MA 02466。
首页|
Cookie 政策|
隐私|
使用条款
您的隐私选择
Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
Explore our brands
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
Advertise
NEWSLETTER SIGN-UP
Cybersecurity Topics
World
The Edge
DR Technology
Events
Resources
СLOUD SECURITY
THREAT INTELLIGENCE
VULNERABILITIES & THREATS
CYBERATTACKS & DATA BREACHES
NEWS
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
Elizabeth Montalbano,Contributing Writer
September 28, 2026
4 Min Read
SOURCE: BOY WWIRAT VIA GETTY IMAGES
An agentic AI attacker turned compromised Microsoft Azure credentials into a weapon for destroying cloud resources in minutes in what appeared to be a ransomware or extortion attack.
Microsoft attributed the attack to JadePuffer, which it tracks as Storm-3168. Sysdig researchers identified the group in July as the first documented large language model (LLM)-driven ransomware operation.
In this case, JadePuffer compromised two legitimate service principals and then spent hours mapping the victim's environment, according to a Microsoft Security Research blog post published on Sept. 25. After performing reconnaissance, the attacker launched a highly automated destruction campaign that attempted to wipe storage, applications, and databases while targeting backup and recovery controls.
As a whole, the activity is consistent with tactics that support ransomware and extortion operations, Microsoft said. "However, we did not observe a ransom note or confirm successful data exfiltration in the activity described here," according to the post, attributed to Microsoft Security Research and researchers Yossi Weizman and Tushar Mudi.
Related:How to Build a SASE Framework for Modern Cybersecurity
Reconnaissance First, Then Destruction
Microsoft detailed the attack, which took place in early June, in which JadePuffer compromised two service principals belonging to the same Azure tenant. One performed reconnaissance and resource discovery; the other handled discovery, destructive operations, and credential collection.
The first compromised service principal spent about 15-1/2 hours mapping virtual machines (VMs), subscriptions, resource groups, and other resources, while conducting more than 300 successful read operations. About 90 minutes after that reconnaissance began, the second service principal enumerated VMs and resource groups across two subscriptions in just five seconds.
"This breadth of activity would give the threat actor visibility across the organization’s Azure environment," Weizman and Mudi wrote.
Sixteen hours later, the second service principal successfully enumerated Azure App Service configuration stores, potentially looking for exposed credentials, and made unsuccessful attempts to look for Azure OpenSearch resources. The service principal also attempted a ListKey operation against a nonexistent storage account.
Less than a second later, the destructive activity began, with more than 100 attempts to delete storage accounts, most of which succeeded. JadePuffer also deleted an Azure Key Vault, Function App, and App Service plan in the same resource group. The same service principal also attempted to delete multiple Azure SQL databases in parallel, but the attempts failed because the attacker used an unsupported API version.
Related:SASE Converges Network & Security Into One Cloud Solution
About 30 minutes after the destructive activity, the service principal made an inventory request for Azure Storage accounts, including Site Recovery-related accounts, followed by more than 30 successful ListKeys requests to retrieve their access keys.
Exposed Secrets in GitHub
Microsoft isn't certain how the attacker initially compromised the service principal, but found that its client ID, client secret, and tenant ID had previously been exposed in plaintext in a public GitHub issue by an employee of the affected organization. The issue was later edited to remove the exposed secret, but the information remained accessible through its public edit history. Microsoft could not confirm whether the exposed credential was used in the attack.
Still, the acknowledgement of credential exposure potentially being a factor "is a useful warning about how a routine cleanup can leave an account exposed," observes Ross Filipek, chief information security officer at Corsica Technologies. "Once attackers hold an application identity, their activity can look like ordinary cloud administration."
Related:Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
The attack expands the known JadePuffer activity into Azure and highlights the potential for AI-orchestrated attacks to coordinate complex post-compromise operations across cloud environments "with greater speed and scale," Microsoft said.
However, one expert says he's not convinced that the attack was completely AI-directed, like JadePuffer's previous activity was. "I agree with Microsoft’s warning about AI-orchestrated attacks, though the Azure evidence shows coordinated automation rather than proving AI directed each step," says Nick Tausek, lead security automation architect at Swimlane.
However, he acknowledges that agentic AI can still be a dangerous adversary.
In fact, Microsoft said that since the beginning of the year, JadePuffer-linked infrastructure has been probing multiple Azure App services across different customers. The agent appears to be testing various ways to infiltrate cloud environments, including through "WordPress administration, PHP-CGI, LangFlow’s code validation endpoint (/api/v1/validate/code), and other web-shell like paths," according to the post.
Protecting Azure Environments From JadePuffer
Indeed, as the capabilities of agentic AI attackers evolve — and autonomous AI attacks become increasingly common to an even frightening degree — defenders must respond in kind, also using AI to mitigate threats, Microsoft advised.
"Rather than requiring analysts to manually follow each individual action, efforts such as Project Perception and MDASH are intended to support a model in which defenders can investigate and respond across increasingly large and complex environments using AI," the researchers wrote.
Microsoft also recommended various mitigations in its post to reduce the risk and impact of activity similar to that conducted by JadePuffer. This advice includes enabling appropriate Microsoft Defender for Cloud plans for critical Azure workloads; protecting and continuously assessing application credentials and secrets; rotating compromised or exposed credentials immediately and establishing credential life-cycle practices; and applying the principle of least privilege to service principals and other workload identities, among other mitigations.
About the Author
Elizabeth Montalbano
Contributing Writer
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
More Webinars
You May Also Like
СLOUD SECURITY
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
by Alexander Culafi
JUL 08, 2026
СLOUD SECURITY
CSA: CISOs Should Prepare for Post-Mythos Exploit Storm
by Alexander Culafi
APR 13, 2026
СLOUD SECURITY
APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials
by Elizabeth Montalbano
APR 13, 2026
СLOUD SECURITY
TeamPCP Turns Cloud Infrastructure Into Crime Bots
by Jai Vijayan
FEB 09, 2026
Featured
Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!
Editor's Choice
APPLICATION SECURITY
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
byNate Nelson
SEP 24, 2026
6 MIN READ
CYBERATTACKS & DATA BREACHES
3 Cyber Threats That Defined the Summer of 2026
byArielle Waldman
SEP 24, 2026
APPLICATION SECURITY
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
byNate Nelson
SEP 24, 2026
5 MIN READ
OCTOBER 8, 2026 | VIRTUAL
Building a Secure AI Strategy for the Enterprise
GET AHEAD OF AI RISKS
Want more Dark Reading stories in your Google search results?
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
Discover More
Black Hat
Omdia
Working With Us
About Us
Meet the Editors
Advertise
Reprints
Join Us
NEWSLETTER SIGN-UP
Follow Us
Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.
Home|
Cookie Policy|
Privacy|
Terms of Use
Your Privacy Choices
首次收录 · 2026-09-29 · 9.62 分