Microsoft AzCopy Abused to Exfiltrate Data
The cybersecurity landscape is facing a new threat as ransomware operators have started using Microsoft’s AzCopy, a trusted command-line tool, to facilitate data exfiltration during attacks. This utility, designed for transferring data to Azure Storage, helps attackers extract sensitive information undetected by exploiting its seamless integration with business operations. Researchers at Varonis Threat Labs discovered incidents where AzCopy was used to quietly siphon data before encryption, bypassing Endpoint Detection and Response systems.
Attackers cleverly weaponize AzCopy by generating Shared Access Signature tokens to transfer stolen data to Azure Blob Storage. They employ advanced command parameters to make the operation mimic legitimate cloud synchronization, evading detection. To cover tracks, attackers delete log files containing transfer records. Organizations must scrutinize outbound connections to Azure and enhance monitoring tactics.
Read more on how misconduct with Microsoft AzCopy evolves in the full article at the link below to stay informed about protecting your infrastructure.
Trusted Azure Utility AzCopy Turned into Data Exfiltration Tool in Active Ransomware Campaigns
