Jessica Entwistle
September 28 2026
Microsoft published threat intelligence on 25 September detailing cloud attacks by a threat actor tracked as Storm-3168, linked to the JADEPUFFER malware family. The Microsoft Security Blog reports that the actor is using compromised Azure service principals to conduct reconnaissance, delete cloud resources, and access credentials across targeted environments. The attacks demonstrate how compromised service accounts with elevated permissions can enable attackers to move laterally across cloud infrastructure, enumerate resources, and cause operational disruption without requiring traditional user credentials. The activity highlights a growing trend of attackers targeting non-human identities in cloud environments, where monitoring and governance often lag behind controls applied to user accounts.
Service principals are non-human identities used to automate tasks, integrate applications, and manage cloud resources across Azure environments. Many UK organisations rely on service principals for DevOps pipelines, infrastructure-as-code deployments, and third-party integrations. When these accounts are compromised, attackers gain persistent access that often bypasses multi-factor authentication and user-focused monitoring. The operational risk is significant because service principals frequently hold broad permissions across subscriptions, resource groups, and sensitive data stores. Unlike user accounts, service principals are often created without expiration dates, rarely have their credentials rotated, and may not be subject to the same access reviews that apply to human identities. This creates an attractive target for attackers seeking long-term access to cloud environments. The Storm-3168 activity demonstrates that threat actors understand this gap and are actively exploiting it to achieve their objectives.
Organisations should review how service principals are created, what permissions they hold, and whether their activity is being monitored effectively. Ensure that service accounts follow the principle of least privilege, with permissions scoped to the specific resources and actions they need to perform. Implement regular credential rotation for service principals and review their access rights as part of routine identity governance. Consider enabling conditional access policies and monitoring for service principal activity, including unusual resource enumeration, deletion events, or access to sensitive data stores. Organisations should also review who has the ability to create and modify service principals and ensure that this capability is appropriately restricted and audited. Where possible, use managed identities rather than service principals with stored credentials, as managed identities reduce the risk of credential theft.
Source: Microsoft Security Blog