Trusted Azure Utility AzCopy Turned into Data Exfiltration Tool in Active Ransomware Campaigns
ID: eb3d12e7-8bc8-56c0-a124-01c01b2c16bf
STIX ID: report--eb3d12e7-8bc8-56c0-a124-01c01b2c16bf
Feed Name: cybersecurityNews.com
Ransomware operators are increasingly weaponizing Microsoft AzCopy — a legitimate Azure data-transfer utility — to exfiltrate sensitive files to attacker-controlled Azure Blob Storage using short-lived SAS tokens, stealthy command-line parameters (e.g., --include-after and --cap-mbps), and by deleting .azcopy logs to remove forensic traces; this technique enables silent double-extortion campaigns that can evade EDR detection and complicate takedown efforts, so organizations should monitor unusual *.blob.core.windows.net traffic, apply UEBA and application whitelisting, and test incident response plans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
