Researchers documented multiple ways attackers can hide command-and-control and data theft inside legitimate Microsoft Azure services, highlighting how trusted cloud traffic can mask malicious activity. One proof-of-concept showed Azure DevOps REST APIs being used without exploiting any software flaw: Windows malware authenticated with a Personal Access Token, queried dev.azure.com, created work items, and stored host data in task fields over HTTPS. The technique requires no attacker-owned infrastructure, blends into normal enterprise traffic, and can leave exfiltrated data preserved in Azure DevOps records until removed; the sample also reportedly avoided detection in sandbox testing.
A separate investigation tied the same cloud-abuse theme to real-world banking malware in Brazil, where a phishing campaign delivered the AllaSenha trojan through invoice-themed lures, malicious .lnk files, PowerShell and Python stages, and an in-memory Delphi loader. The malware used a DGA to reach Azure-hosted endpoints under *.brazilsouth.cloudapp.azure[.]com over raw TCP, then deployed a final payload that stole Brazilian banking credentials and 2FA material, including tokens and QR codes, while using operator-driven overlays to hijack authentication flows. The reporting underscores that Azure infrastructure is being used both experimentally and operationally as a stealthy channel for malware staging, C2, and exfiltration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Delphi DLL "ExecutorLoader," used in the AllaSenha infection chain to inject the final payload into a renamed mshta.exe process, was compiled on 2024-05-02 10:44:22. The report identifies this loader as a key in-memory stage preceding execution of the final banking trojan.
In May 2024, a multi-stage phishing campaign impersonating Brazilian electronic invoice notifications delivered the banking trojan AllaSenha to victims in Brazil. The infection chain used malicious links, a WebDAV-hosted LNK, PowerShell and Python stages, and Azure-hosted infrastructure for staging and command-and-control.
The Azure DevOps abuse post stated that sandbox analysis by ANY.RUN reported no threats detected for the uploaded sample. The result was presented as evidence that benign-looking traffic to Microsoft cloud services can complicate detection.
A blog post demonstrated three proof-of-concept programs that abuse the Azure DevOps REST API as a covert channel for command-and-control or data exfiltration without exploiting an Azure DevOps vulnerability. The examples showed listing projects, creating work items, and storing host information in task fields over HTTPS to dev.azure.com.
HarfangLab published a report detailing AllaSenha as an AllaKore variant targeting Brazilian banking users and using Azure cloud infrastructure for C2. The report documented the phishing chain, malware stages, persistence, and targeting of Brazilian banks and 2FA artifacts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 74 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourceharfanglab.io
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.