Skip to content

other

JADEPUFFER

JadePuffer (Storm-3168) is a threat actor using autonomous AI agents to plan and execute ransomware and extortion attacks in cloud environments.

Known aliases

  • Storm-3168

Relationships

No evidence-backed relationships are recorded.

Current stories

security6 publishers

Storm-3168 mapped an Azure tenant for 17 hours before a seven-minute deletion run

Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 70%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence70
security5 publishers

Microsoft's 2026 defense report says cross-system intrusions become clearer when signals are joined

Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 63%
Investor
Investor 14%

Reality

Evidence55
Adoption
Insufficient
Hype gap−15
Incentives60
Confidence60