A ransomware group has destroyed data and backups in a Microsoft Azure environment after exfiltrating sensitive information, which experts describe as a significant escalation in cloud-based attacks.
The threat actor, tracked as Storm-0501, gained complete control over a victim's Azure domain by exploiting privileged accounts.
Microsoft researchers said the group used native Azure tools to copy data before systematically deleting resources to block recovery efforts.
After exfiltration, Storm-0501 used AzCopy to steal storage account contents and erase cloud assets. Immutable resources were encrypted instead.
The group later contacted the victim via Microsoft Teams using a compromised account to issue ransom demands.
,