Storm-3168 is a cybercriminal threat actor tracked by Microsoft and linked to JADEPUFFER agentic-ransomware operations. In June 2026, the actor compromised two Azure service principals in a single tenant and used their existing permissions to conduct extensive cloud-environment discovery, destructive operations, and Azure Storage access-key collection. One identity performed prolonged enumeration of virtual machines, subscriptions, resource groups, and other Azure resources, while another rapidly enumerated resources and application configuration stores before initiating destructive activity. Storm-3168 attempted to delete more than 100 Azure Storage accounts, successfully deleting most of those targeted, and deleted a Key Vault, Function App, and App Service plan. It also attempted parallel deletion of Azure SQL databases and targeted Azure Site Recovery and Azure Backup protections, indicating an effort to impair recovery. Some destructive operations were prevented by Azure resource locks and account-level deletion protection. After the deletion activity, the actor obtained access keys for numerous Azure Storage accounts, including accounts associated with Site Recovery. The use of multiple compromised identities, concurrent token activity, and rapid division of operations indicates automated or scripted execution. The activity is consistent with ransomware- or extortion-oriented cloud attacks, although no ransom note, successful data exfiltration, or direct AI control of the intrusion was confirmed. Microsoft did not establish the initial-access method; publicly exposed service-principal credentials were identified as a possible but unconfirmed access vector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a destructive, likely extortion-focused Azure intrusion using two compromised service principals. One identity performed extensive cloud-resource discovery, while another rapidly deleted Azure Storage accounts and other resources, targeted recovery protections, and retrieved Azure Storage access keys, including keys associated with Site Recovery.
Conducted a likely extortion-focused destructive Azure intrusion using compromised cloud application credentials. The actor performed extensive resource discovery, attempted deletion of Azure Storage accounts, Key Vaults, Function Apps, App Service plans, SQL databases, and backup/recovery protections, then retrieved Storage account keys that could enable subsequent data collection or recovery disruption.
Conducted Azure-focused cloud intrusion activity consistent with preparation for ransomware or extortion: hijacking service-principal identities, enumerating cloud assets, attempting to collect storage access keys, deleting storage and application resources, and attempting to impair backup and recovery protections. No ransom note, confirmed data exfiltration, or confirmed successful Azure SQL database deletion was observed in this activity.
A cloud-focused, suspected ransomware/extortion actor that abuses stolen Azure service-principal credentials for rapid automated reconnaissance, destructive operations, recovery disruption, and credential/key harvesting. Microsoft did not confirm an initial-access method, data exfiltration, or a ransom note in this incident.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.