AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks
ID: eec17227-4635-5455-a515-c1a7dedf6517
STIX ID: report--eec17227-4635-5455-a515-c1a7dedf6517
Feed Name: GBHackers
**Executive Summary:** Ransomware operators are increasingly abusing Microsoft's AzCopy utility to stealthily exfiltrate sensitive data to attacker-controlled Azure Blob storage before encrypting systems; observed groups (e.g., BianLian, Rhysida) use valid credentials/SAS tokens, throttling, and log deletion to evade detection, and organizations should adopt data-centric controls, UEBA, network restrictions, application control, and incident plans to detect and respond to cloud-based exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
