Ransomware gangs now abuse Microsoft Azure tool for data theft
ID: 973fa0e8-fa99-5d33-9f0f-124d7cfb1d29
STIX ID: report--973fa0e8-fa99-5d33-9f0f-124d7cfb1d29
Feed Name: Bleeping Computer
Ransomware gangs including BianLian and Rhysida are increasingly using Azure Storage Explorer and AzCopy to steal and stage exfiltrated files in Azure Blob storage — attackers may install dependencies and upgrade .NET, run multiple instances to accelerate uploads, and leverage Azure's trusted status to evade detection; the report highlights detection points such as AzCopy logs at %USERPROFILE%\.azcopy and outbound traffic to *.blob.core.windows.net, and recommends monitoring AzCopy execution, Azure blob endpoints/IP ranges, and enabling session logout to prevent reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
