Azure Resources Wiped in 7 Minutes as Storm-3168 Exploits Compromised Service Principals
Microsoft Security Research documented a critical cloud attack by threat group Storm-3168, in which two compromised Azure service principals carried out coordinated reconnaissance and destruction within a single victim tenant. One service principal conducted over 300 read operations across roughly 15.5 hours, while a second rapidly enumerated virtual machines and resource groups in approximately five seconds. About 16 hours after initial reconnaissance, the second principal deleted multiple storage accounts, a Key Vault, a Function App, and an App Service plan in a destructive sequence lasting around seven minutes. Approximately 30 minutes after the deletions, the attacker re-enumerated storage accounts and successfully issued over 30 ListKeys requests to harvest access credentials. Attempts to disable Site Recovery and backup protection locks were also observed, though those specific actions failed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in