Skip to content
Storm-3168 and Storm-2570: Evolving Ransomware Tactics in Cloud Environments

Storm-3168 and Storm-2570: Evolving Ransomware Tactics in Cloud Environments

First seen 25 Sep 2026, 21:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 23:27 UTC
  • •JADEPUFFER (Storm-3168) uses compromised service principals for Azure attacks.
  • •Storm-2570 employs consistent tools across RaaS platforms for lateral movement.
  • •Defenders should enforce least privilege access and monitor for unauthorized tools.

Microsoft Security Research has identified a new threat actor, JADEPUFFER, linked to Storm-3168, which employs compromised service principals for destructive operations in Azure environments. The attacks involve extensive resource enumeration and credential collection, targeting Azure Storage Accounts, SQL databases, and Virtual Machines. Concurrently, Storm-2570 operates across multiple Ransomware-as-a-Service platforms, using consistent tools like MeshAgent and PsExec for lateral movement and data exfiltration. Both threats highlight a shift towards AI-driven and cloud-focused ransomware strategies, necessitating enhanced defensive measures. Organizations are urged to enforce least privilege access, monitor for unauthorized RMM tools, and utilize Microsoft Defender for Cloud protections. The evolving tactics of these ransomware groups underscore the need for proactive security measures in cloud infrastructures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
Initial reconnaissance by compromised service principals
A compromised service principal enumerated Azure resources for over 15 hours, gathering extensive visibility.
Microsoft
2026-06-01
Destructive operations initiated
A second compromised service principal executed destructive operations and credential collection shortly after reconnaissance.
Microsoft
2026-09-25
Microsoft publishes findings on Storm-3168
Microsoft details the cloud-focused operations of JADEPUFFER, emphasizing the need for enhanced defenses.
Microsoft
2026-09-25
Socprime reports on Storm-2570
Socprime outlines the consistent tradecraft of Storm-2570 across multiple RaaS platforms, highlighting its toolkit.
Socprime

More articles in this cluster (3)

Following this threat?

Track Storm-2570, ROADTools and MeshAgent in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed