AzCopy - Tool

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 11, 2025
Last Seen
March 4, 2026

AzCopy is a tool tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity March 4, 2026.

Overview

AzCopy is a Microsoft command-line utility used to copy data to and from Azure Storage services. While legitimate and widely deployed for data transfer, threat actors can abuse AzCopy to exfiltrate data or move ransomware payloads, making its activity hard to distinguish from normal operations. Its potential for stealthy data movement makes monitoring AzCopy usage important in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • Trusted Azure Utility AzCopy Turned into Data Exfiltration Tool in Active Ransomware Campaigns — Cybersecuritynews · March 4, 2026
  • AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks — Gbhackers · March 4, 2026
  • How a CPU spike led to uncovering a RansomHub ransomware attack — Bleepingcomputer · November 11, 2025

CVSS v3.1 Breakdown