logo

Ransomware gangs now abuse Microsoft Azure tool for data theft

ID: 973fa0e8-fa99-5d33-9f0f-124d7cfb1d29

STIX ID: report--973fa0e8-fa99-5d33-9f0f-124d7cfb1d29

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ransomware gangs including BianLian and Rhysida are increasingly using Azure Storage Explorer and AzCopy to steal and stage exfiltrated files in Azure Blob storage — attackers may install dependencies and upgrade .NET, run multiple instances to accelerate uploads, and leverage Azure's trusted status to evade detection; the report highlights detection points such as AzCopy logs at %USERPROFILE%\.azcopy and outbound traffic to *.blob.core.windows.net, and recommends monitoring AzCopy execution, Azure blob endpoints/IP ranges, and enabling session logout to prevent reuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.