Jessica Entwistle
September 29 2026
Microsoft has published threat intelligence warning that a threat actor it tracks as JadePuffer has been hijacking Azure identities and using them to abuse cloud resources. The Register reports that the activity involves compromising Azure credentials and then using those identities to spin up cloud resources for purposes that appear consistent with ransomware or cryptomining operations. Microsoft describes the activity as resembling agentic ransomware behaviour, where attackers use compromised cloud identities not just for data theft but to manipulate or abuse the victim's own cloud infrastructure. The threat intelligence does not specify how the identities were initially compromised, but the pattern suggests credential theft, phishing, or exploitation of exposed secrets such as API keys or service principal credentials.
This type of attack highlights the operational risk that comes with cloud identity being the primary control plane for access to infrastructure, data and services. Once an attacker has valid Azure credentials, they can operate within the victim's environment in ways that may not immediately trigger traditional security alerts, particularly if the activity looks like legitimate resource provisioning. For organisations using Azure, this reinforces the importance of identity security, monitoring for unusual resource creation or configuration changes, and ensuring that cloud billing and usage anomalies are reviewed regularly. It also underscores the risk of exposed API keys, service principal credentials, or overly permissive role assignments that allow broad access to cloud resources. The fact that Microsoft is describing this activity as agentic ransomware suggests that attackers are increasingly using compromised cloud identities not just for data exfiltration but to actively manipulate and abuse the victim's own infrastructure, which can create significant operational and financial impact.
UK organisations using Azure should review how cloud identities are protected, how service principals and API keys are managed, and whether monitoring is in place to detect unusual resource provisioning or configuration changes. This includes ensuring that multi-factor authentication is enforced for all Azure accounts, that service principal credentials are rotated regularly and stored securely, and that role-based access control is configured to follow the principle of least privilege. Organisations should also ensure that cloud billing alerts are configured to flag unexpected usage spikes, as this can be an early indicator of compromised credentials being used to abuse cloud resources. It is also worth reviewing whether logging and monitoring are in place to detect unusual patterns of resource creation, deletion or configuration changes, and whether security teams have visibility into cloud activity that may not trigger traditional endpoint or network security alerts. Finally, organisations should consider whether incident response plans include scenarios where cloud identities are compromised and used to manipulate cloud infrastructure, and ensure that the teams responsible for cloud security, identity management and billing are aligned and able to respond quickly to suspicious activity.
Source: The Register