AzCopy is a tool tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity March 4, 2026.
AzCopy is a Microsoft command-line utility used to copy data to and from Azure Storage services. While legitimate and widely deployed for data transfer, threat actors can abuse AzCopy to exfiltrate data or move ransomware payloads, making its activity hard to distinguish from normal operations. Its potential for stealthy data movement makes monitoring AzCopy usage important in cybersecurity.
Ransomware operators have begun misusing Microsoft's AzCopy, a legitimate command-line utility, to facilitate data exfiltration in ongoing attacks. This shift marks a significant change in tactics, as attackers leverage…