# Attackers Weaponize Stolen Azure Service Principals for Mass Resource Deletion
JADEPUFFER, a destructive threat actor tracked by Microsoft as Storm-3168, has demonstrated a new attack capability by leveraging compromised Azure service principals to delete cloud resources across a victim organization's Microsoft Azure environment.
The June 2026 incident unfolded over approximately 18 hours, marking what Microsoft characterizes as an evolution in the threat actor's operational tactics. Rather than relying on traditional lateral movement or credential theft of human user accounts, JADEPUFFER exploited compromised service principals, the Azure equivalent of application-level service accounts that carry persistent authentication tokens without human involvement.
Service principals represent a particularly attractive target for attackers seeking to maintain access and execute destructive operations. These accounts typically possess elevated permissions and operate outside normal interactive authentication flows, making them difficult to monitor and detect through standard user activity logging. Once compromised, service principals grant attackers the ability to execute API calls directly against Azure resources with minimal visibility.
The destructive phase of this attack involved systematic deletion of Azure resources. Microsoft has not disclosed the full scope of deleted resources, but the 18-hour operational window suggests widespread targeting across multiple resource types and subscriptions. Organizations operating multi-tenant or complex Azure environments face elevated risk, as compromised service principals within shared infrastructure can propagate damage across numerous projects and business units simultaneously.
The targeting of service principals reflects a strategic shift in how sophisticated attackers approach cloud environments. Traditional Azure security measures focus heavily on user authentication and conditional access policies. Service principal compromise bypasses these controls entirely. Attackers can extract service principal credentials through numerous vectors, including exposed configuration files in source code repositories, overly permissive secret management practices, or compromise of developer workstations that store credential material locally.
JADEPUFFER's activity history positions the group as operationally sophisticated. Previous campaigns attributed to this actor have focused on destructive objectives rather than data exfiltration, aligning with suspected motivations tied to geopolitical or state-sponsored activities. The June 2026 incident demonstrates that the group actively refines its capabilities to exploit cloud-native attack surfaces.
Organizations running Azure workloads should prioritize service principal security immediately. This includes auditing all service principals in use, rotating credentials for all privileged accounts, enforcing multi-factor authentication even for service principals where technically possible, implementing least-privilege access policies through Azure role-based access control (RBAC), and enabling comprehensive logging for service principal activities through Azure Monitor and Sentinel.
Azure's native tools provide visibility into service principal behavior through audit logs and activity monitoring, but many organizations fail to configure these logging capabilities or alert on suspicious deletion patterns. Implementing Azure Policy to restrict resource deletion actions and enforcing resource locks on critical infrastructure can provide additional defense against wholesale deletion attacks.
The incident also highlights the risk of overprivileged service principals. Many organizations grant service principals overly broad permissions "just in case," without regularly auditing whether those permissions remain necessary. A service principal designed for a single application should never possess organization-wide deletion rights.
