logo

AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks

ID: eec17227-4635-5455-a515-c1a7dedf6517

STIX ID: report--eec17227-4635-5455-a515-c1a7dedf6517

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** Ransomware operators are increasingly abusing Microsoft's AzCopy utility to stealthily exfiltrate sensitive data to attacker-controlled Azure Blob storage before encrypting systems; observed groups (e.g., BianLian, Rhysida) use valid credentials/SAS tokens, throttling, and log deletion to evade detection, and organizations should adopt data-centric controls, UEBA, network restrictions, application control, and incident plans to detect and respond to cloud-based exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.