{"id":7910,"date":"2025-10-24T10:03:28","date_gmt":"2025-10-24T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/threat-actors-attacking-azure-blob-storage-to-compromise-organizational-repositories\/"},"modified":"2025-10-24T10:03:28","modified_gmt":"2025-10-24T10:03:28","slug":"threat-actors-attacking-azure-blob-storage-to-compromise-organizational-repositories","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/threat-actors-attacking-azure-blob-storage-to-compromise-organizational-repositories\/","title":{"rendered":"Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories"},"content":{"rendered":"<p>    Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations\u2019 critical code repositories and sensitive data.<\/p>\n<p>This emerging threat exploits misconfigured storage access controls to establish persistence and exfiltrate valuable intellectual property.<\/p>\n<p>The attack vector represents a significant shift in how threat actors are approaching cloud infrastructure, moving beyond traditional endpoint-focused attacks toward enterprise storage systems.<\/p>\n<p>The campaign has been linked to multiple threat groups operating across different sectors, including finance, technology, and critical infrastructure.<\/p>\n<p>Microsoft analysts noted that the attacks typically begin with credential harvesting through phishing campaigns and malware-based information stealers.<\/p>\n<p>Once initial access is established, operators conduct <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> to identify accessible Azure Blob Storage instances with weak or default access policies.<\/p>\n<p>The threat actors then systematically enumerate containers to locate valuable repositories, configuration files, and backup data.<\/p>\n<p>Microsoft researchers <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/10\/20\/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> a critical component of this operation involving SharkStealer, a Golang-based infostealer that employs an advanced communication technique called EtherHiding to evade traditional detection mechanisms.<\/p>\n<p>This malware family utilizes the BNB Smart Chain Testnet as a command-and-control dead-drop, retrieving encrypted command instructions through smart contract calls rather than direct domain-based communications.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-analysis-of-etherhiding-pattern-in-azure-attacks\"><strong>Technical Analysis of EtherHiding Pattern in Azure Attacks<\/strong><\/h2>\n<p>The sophistication of these operations lies in how threat actors combine traditional <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a> with blockchain-based obfuscation techniques. SharkStealer initiates contact with BNB Smart Chain nodes using Ethereum JSON-RPC calls targeting specific smart contracts.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjj7LW0CgtMudDi7VHe01_VuhBPNHDEcpYahafMN_GSSbc_BiDe395sdzZdd0JRJx1oBhygGn-mqfB53Ip5nnYuXsLdEiVAeYhULVQNabptLW6k3z8Sm-nxUmVq__GiZQHxa5sb6L9YEglPId0PHoT_U-V2GSBuJelKMUbMAREwqm_NA3VMK_xYfvdgmKI\/s16000\/Attack%2520techniques%2520that%2520abuse%2520Blob%2520Storage%2520along%2520the%2520attack%2520chain%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack techniques that abuse Blob Storage along the attack chain (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p>The malware executes eth_call requests to predetermined contract addresses, receiving tuples containing an initialization vector and encrypted payload.<\/p>\n<p>Using a hardcoded AES-CFB encryption key embedded within the binary, the malware decrypts the returned data to extract current C2 server coordinates.<\/p>\n<p>This methodology creates significant detection challenges because network traffic analysis reveals only legitimate blockchain node communications, making it extremely difficult to distinguish malicious activity from benign cryptocurrency wallet interactions.<\/p>\n<p>The use of public blockchain infrastructure as a dead-drop mechanism provides threat actors with remarkable resilience against traditional takedown operations and domain blocking strategies.<\/p>\n<p>In observed campaigns, once <a href=\"https:\/\/cybersecuritynews.com\/sharkstealer-using-etherhiding-pattern\/\" target=\"_blank\" rel=\"noreferrer noopener\">SharkStealer<\/a> compromises a system, it harvests Azure credentials stored in browser caches, configuration files, and credential managers.<\/p>\n<p>These stolen credentials grant direct access to Azure Blob Storage containers without triggering standard access controls.<\/p>\n<p>Threat actors then establish secondary connections to Azure Storage, downloading entire repositories containing source code, API keys, and sensitive configuration data.<\/p>\n<p>The combination of EtherHiding-based command infrastructure with Azure Storage access creates a particularly dangerous threat profile that organizations must actively defend against through credential rotation, access reviews, and <a href=\"https:\/\/cybersecuritynews.com\/network-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring<\/a> for anomalous blockchain-based communications originating from internal networks.<\/p>\n<p>Organizations should implement strict Azure Storage authentication policies, enforce multi-factor authentication on administrative accounts, and deploy behavioral monitoring to detect unusual API access patterns.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-azure-blob-storage\/\">Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-azure-blob-storage\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations\u2019 critical code repositories and sensitive data. This emerging threat exploits misconfigured storage access controls to establish persistence and exfiltrate valuable intellectual property. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7910","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7910"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7910"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7910\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}