Agentic Driven Cloud Attack Using Compromised Service Principals

Published on 01-Oct-2026 12:00:00

Executive Summary

Cyber Threat Intelligence of BGD e-GOV CIRT is issuing this advisory regarding a recently documented automated cloud attack campaign in which compromised service principal’s/workload identities were used to perform reconnaissance, resource discovery, destructive operations and credential collection across a cloud environment.

The investigated activity involved two compromised service principals. One primarily performed reconnaissance, while the second performed extensive discovery followed by destructive operations and credential collection. The attacker enumerated virtual machines, subscriptions, resource groups, storage accounts, application services and other cloud resources before initiating a rapid destructive sequence.

During the destructive phase, the attacker attempted 100+ storage-account deletions, deleted a Key Vault, Function App and App Service plan, attempted database deletion, and attempted to interfere with backup and recovery protection mechanisms. Approximately 30 minutes later, the compromised identity successfully performed 30+ storage-account key retrieval operations, potentially providing access to sensitive data.

The activity is notable because the destructive actions were performed using legitimate cloud identities and their existing permissions, rather than requiring conventional ransomware malware on endpoints. The observed timing and parallel token activity strongly indicate scripted or automated execution.

No ransom notes or successful data exfiltration was confirmed in the investigated activity. However, the combination of resource destruction, recovery-control targeting and credential collection is consistent with activity that could support ransomware or extortion operations.

Key Findings

The campaign demonstrates a significant shift from traditional endpoint-centric ransomware toward cloud-native destructive operations. The investigated activity demonstrates that identity compromise can itself become the destructive mechanism.

· Compromised service principals were used as the primary execution identities.

· Cloud reconnaissance preceded destructive activity.

· More than 300 successful read operations were observed during one reconnaissance period.

· The attacker used multiple tokens for parallel operations.

· More than 150 destructive or credential-related operations were attempted.

· More than 100 storage-account deletion attempts were observed.

· Key Vault, Function App and App Service resources were deleted.

· Azure SQL database deletion was attempted but unsuccessful.

· Backup and recovery protection mechanisms were targeted.

· More than 30 successful storage-account key retrievals were performed.

· Operations followed the permissions already assigned to the compromised identity.

· The activity showed characteristics of highly automated/scripted cloud operations.

No successful data exfiltration or ransom note was confirmed in the investigated case.