AzCopy is a legitimate Microsoft command-line utility for transferring data to and from Azure Storage that has been abused by threat actors, including ransomware operators, as a living-off-the-land exfiltration tool. Reported use includes stealthy theft of sensitive files to attacker-controlled Azure Blob Storage over standard HTTPS prior to encryption in double-extortion operations. The utility runs as a standalone executable without installation, and the activity may blend with normal enterprise Azure usage; the provided content states some EDR platforms may not flag it because it is a recognized enterprise tool. Observed attacker tradecraft includes embedding short-lived Shared Access Signature (SAS) tokens directly in AzCopy commands to authenticate to attacker-controlled storage accounts, using --include-after to limit transfers to recently modified files, and --cap-mbps to throttle bandwidth and reduce detection from traffic spikes. AzCopy writes logs by default to a hidden .azcopy directory in the executing user profile, and attackers were reported to delete that directory after exfiltration to remove evidence. In one FortiGuard-reported 2025 intrusion attributed to the Interlock ransomware group targeting a North American education organization, the adversary copied the AzCopy executable as win64.exe (SHA1: BE39DBADFC9CFC494F1B7BF3A04E49C336E0FA0D) and exfiltrated more than 250GB of data from the victim’s primary file server to an Azure storage bucket on September 15, 2025; FortiGuard stated this was the only bulk exfiltration observed in that intrusion. High-confidence indicators and artifacts mentioned in the content include outbound connections to Azure Blob Storage endpoints such as *.blob.core.windows.net, SAS-token-authenticated AzCopy command lines, the hidden .azcopy log directory, and the renamed executable win64.exe with the above SHA1 in the Interlock case.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"including AZcopy, have also been distributed for extensive data exfiltration ahead of ransomware delivery"
AzCopy is used for cloud-to-cloud data theft from victim Azure storage to attacker-controlled storage.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate Microsoft Azure Storage command-line utility that threat actors are abusing for stealthy data exfiltration to attacker-controlled Azure Blob Storage using SAS tokens, often throttling transfer rates and filtering by modified date to blend into normal HTTPS cloud traffic; attackers may delete the .azcopy log directory afterward to reduce forensic evidence.
Legitimate Microsoft command-line utility abused to exfiltrate large volumes of data to an Azure storage bucket as part of the extortion phase preceding encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.