Skip to content
ransomwareAgentic AIAI SecurityLLM

Storm-3168 deploys Azure AI agents to automate ransomware attacks

2 min read
Share

What the group did

JadePuffer, tracked as Storm-3168 by Microsoft MSTIC, deployed a multi-step attack chain using Azure AI Foundry agents provisioned inside victim environments. After gaining initial access through phishing and credential theft, the actor created agent deployments within the victim's own Azure tenant. The agents handled reconnaissance, lateral movement, and ransomware payload delivery autonomously, with each agent passing context to the next via structured prompts. The ransomware payload itself was not technically novel. The delivery infrastructure built on top of legitimate cloud AI services was.

Why using the victim's own cloud tenant matters

Provisioning malicious agents inside the victim's Azure environment gives the attacker several advantages. Actions originate from trusted infrastructure, which makes detection based on known-bad IP addresses or external indicators of compromise ineffective. Agent activity logs are interleaved with legitimate workload telemetry, making manual review slow. The attacker also inherits whatever IAM permissions the compromised credential held, including potential cross-service access to storage, compute, and Key Vault. The agent-based delivery mechanism makes the attack more adaptive: if one step fails, the agent can attempt alternative paths without the attacker taking manual action.

Detection opportunities

The attack chain leaves detectable signals at several points. Unusual agent provisioning in Azure AI Foundry, especially new deployments that follow a credential anomaly, is the highest-signal indicator before execution begins. During the attack, watch for agents making API calls to internal resources that the associated user account has not previously accessed, and for bulk file enumeration crossing storage account boundaries. After execution, look for ransomware-associated file extension changes alongside agent workspace activity in the same time window.

What to do now

Audit which service principals and user accounts in your environment have permission to deploy to Azure AI Foundry. Apply least privilege: most users and service accounts have no legitimate reason to provision AI agents. Enable Microsoft Defender for Cloud anomaly alerts for AI Foundry workspaces and route those alerts to your SIEM. Review Conditional Access policies to ensure that a single compromised credential cannot reach sensitive resources unilaterally. If your organization uses Azure AI services legitimately, establish a baseline of expected agent deployment frequency so anomalous provisioning is identifiable.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization is evaluating controls for cloud AI workloads.

Related articles