Type
Campaign
Actors
Pub. date
September 26, 2026
Initial access
1-day vulnerabilityExposed secret
Impact
RansomOp
Observed techniques
Status
Finalized
Last edited
Oct 4, 2026 1:18 PM
Multiple sources reported malicious activity linked to JADEPUFFER (Storm-3168), an agentic ransomware operation, during June 2026. This attacker has been observed leveraging exposed secrets and exploiting vulnerabilities in Internet-facing software for initial access to cloud environments. Having done so, they have either encrypted or deleted accessible data. JADEPUFFER has targeted various managed Azure services, as well as self-hosted instances of Langflow, Nacos, WordPress, PHP-CGI, MySQL, and MinIO for exploitation and data destruction.