Ransomware Strikes Azure Storage: Are You Ready?
ID: d3eb50dd-4f3b-5c84-82b0-d4a4fd29bd4f
STIX ID: report--d3eb50dd-4f3b-5c84-82b0-d4a4fd29bd4f
Feed Name: Mitiga
This report describes a surge in cloud-targeted ransomware activity with examples of BlackCat/ALPHV abusing Azure Storage Account access (keys and RBAC) to encrypt blobs and backups; it outlines how attackers obtain access (access keys, RBAC roles, SAS tokens), encryption methods (mass download-reencrypt-reupload, misuse of Key Vault), detection opportunities in Azure activity and resource logs, and practical mitigations including network restrictions, managed identities, RBAC, key rotation, and Azure data protection features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
