By Abhishek Jadhav
Publication Date: 2026-09-29 12:35:00
Microsoft Security Research traced an Azure intrusion to Storm-3168. The attacker used two compromised service principals to map the victim’s cloud environment, delete resources, and retrieve storage account access keys.
One identity focused on discovery, and the other carried out reconnaissance, destructive operations, and credential collection.
Service principals are workload identities that allow applications and automated services to access cloud resources. They are not employee accounts or identities created for AI agents.
Microsoft says the destruction, attempts to interfere with recovery protections, and collection of storage credentials were consistent with ransomware or extortion activity.
The first service principal performed more than 300 successful discovery operations over approximately 15.5 hours.
The second attempted more than 150 destructive or credential-related operations within 35 minutes.
The main destructive sequence lasted about seven…



