Microsoft Warns of Cloud-Destroying Attacks Using Stolen Azure Identities
Microsoft has revealed that a cyber criminal group known as Storm-3168, previously linked to the first documented case of AI-driven ransomware, has also been using stolen Azure identities to carry out destructive attacks against cloud storage and other resources. The group compromised two 'service principals' (machine identities used to access cloud services) belonging to the same organisation and used them over an 18-hour period to map out an entire Azure environment before destroying resources and collecting credentials.
One compromised identity was used purely for reconnaissance, conducting over 300 successful read operations across virtual machines, subscriptions and resource groups to build a detailed picture of the target's cloud environment. A second identity, activated 90 minutes later, moved quickly to read resources across multiple subscriptions before the group carried out destructive operations and gathered further credentials that could support future data theft.
Microsoft has not confirmed exactly how the service principals were first hijacked, but noted that an employee at the affected organisation had previously leaked client IDs, client secrets and tenant IDs in plain text on a public GitHub page. The company also flagged ongoing probing of Azure App services linked to this same threat actor since early this year, suggesting the group is actively hunting for further targets.