Socprime Storm-3168 and Storm-2570: Evolving Ransomware Tactics in Cloud Environments
Article Content
- •JADEPUFFER (Storm-3168) uses compromised service principals for Azure attacks.
- •Storm-2570 employs consistent tools across RaaS platforms for lateral movement.
- •Defenders should enforce least privilege access and monitor for unauthorized tools.
Microsoft Security Research has identified a new threat actor, JADEPUFFER, linked to Storm-3168, which employs compromised service principals for destructive operations in Azure environments. The attacks involve extensive resource enumeration and credential collection, targeting Azure Storage Accounts, SQL databases, and Virtual Machines. Concurrently, Storm-2570 operates across multiple Ransomware-as-a-Service platforms, using consistent tools like MeshAgent and PsExec for lateral movement and data exfiltration. Both threats highlight a shift towards AI-driven and cloud-focused ransomware strategies, necessitating enhanced defensive measures. Organizations are urged to enforce least privilege access, monitor for unauthorized RMM tools, and utilize Microsoft Defender for Cloud protections. The evolving tactics of these ransomware groups underscore the need for proactive security measures in cloud infrastructures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Storm-2570, ROADTools and MeshAgent in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…