JADEPUFFER 공격자가 Azure 리소스를 삭제하기 위해 서비스 주체를 악용한 사건이 발생했다.
JADEPUFFER라는 위협 행위자가 Microsoft Azure 환경 내에서 서비스 주체를 악용하여 파괴적인 행동을 orchestrate한 것으로 관찰되었다. 이 공격은 2026년 6월 초에 발생했으며, 약 18시간에 걸쳐 진행되었다. Microsoft는 이 활동을 Storm-3168이라는 이름으로 추적하고 있으며, 이는 위협 행위자의 기술이 진화하고 있음을 나타낸다.
JADEPUFFER attackers misused service principals to delete Azure resources.
The threat actor known as JADEPUFFER has been observed conducting destructive actions within a Microsoft Azure environment using compromised service principals. The attack occurred in early June 2026, lasting approximately 18 hours. Microsoft, tracking this activity as Storm-3168, has noted this as an evolution in the actor's tradecraft.