# Holding blobs for ransom: Four methods for Azure Storage ransomware

DevFeed: [Holding blobs for ransom: Four methods for Azure Storage ransomware](<https://devfeed.tech/articles/holding-blobs-for-ransom-four-methods-for-azure-storage-ransomware-8276.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/azure-blob-storage-ransomware-four-methods/>)

Author: Jonah Feldman

Published: 2026-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [Security](<https://devfeed.tech/topics/security.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [c](<https://devfeed.tech/tags/c.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [http](<https://devfeed.tech/tags/http.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>), [storage](<https://devfeed.tech/tags/storage.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

## AI overview

This security research article examines four ways threat actors can abuse Azure Storage to encrypt victim blobs and hold them for ransom. It explains the attack methods, required permissions, detection event codes, Azure protections, and ways those protections may be circumvented, with comparisons to AWS S3 ransomware techniques.

## Source excerpt

This post explores four vectors for threat actors to abuse Azure Storage to maliciously encrypt victim blobs, including step-by-step explanations and event codes for detection.