HomeSecurityMicrosoft Azure is being used to host malware

Microsoft Azure is being used to host malware

Microsoft's Azure cloud services have become an attractive choice for cybercriminals to store malicious content. From phishing templates to malware and command and control services, it seems that crooks have found a new place to showcase their talents.

Azure

Just this month, BleepingComputer reported on two incidents involving malware on Azure. In one case, there were about 200 websites featuring tech support scams hosted on the platform.

In another article published this week, it is said that Azure is being used to host a phishing template for Office 365. Since both products come from Microsoft, the scam appears as a legitimate login request, increasing the success rate.

It appears that these are not isolated incidents. Security researchers at JayTHL and MalwareHunterTeam found malware in Azure and reported it to Microsoft on May 12.

According to cybersecurity firm AppRiver, the reported piece of malware along with other samples uploaded later were still present in Microsoft's Azure infrastructure on May 29.

“It is obvious that Azure is not currently detecting malware residing on Microsoft servers,” says David Pickett of AppRiver.

One of the samples, 'searchfile.exe', was found by the VirusTotal on April 26 and detected by Windows Defender.

The same goes for the malware detected by the two researchers, “printer / prenter.exe”, which is an uncompressed portable executable file, specifically designed to evade detection when downloaded by endpoint security solutions.

However, Windows Defender will block the malicious file when users try to download it to their device.

Pickett says that when executing 'printer.exe' the command line is called to run the C# compiler and thus activate the payload.

JayTHL clarifies that the sample appears to be a simple “agent” that runs whatever command it receives from the command and control server.

Microsoft Azure wouldn't be the first well-known platform used to store malicious content. Google Drive, Dropbox, and Amazon Web Services are just a few examples. Typically, cybercriminals subvert legitimate websites and use them to host malicious content, but they're also willing to take advantage of any opportunity to do their job, especially if the risk and effort involved are low.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS