BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage — Threadlinqs Intelligence
As of 2026-07-26, BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage is a high-severity ransomware threat attributed to BlackCat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1712 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: BlackCat · FINANCIAL
BlackCat/ALPHV affiliates compromised a Sophos Central MSSP console via a LastPass-stolen OTP, then used the updated Sphynx (BlackCat 3.0) encryptor with an embedded, Base64-encoded Azure Storage
In September 2023, Sophos X-Ops incident responders investigated a BlackCat/ALPHV (RaaS, active since November 2021, Rust-based, tracked by Secureworks as GOLD BLAZER) intrusion in which affiliates gained access to a customer's Sophos Central management console using a one-time password stolen from the victim's LastPass password-vault Chrome browser extension. With console access, the attackers disabled Sophos Tamper Protection and altered security policies, then deployed an updated variant of the group's 'Sphynx' encryptor (internally called BlackCat 3.0, first introduced February 2023) that had gained support for custom/embedded credentials in an August 2023 update. That variant embeds the Impacket networking framework and the Remcom remote-execution tool for lateral movement across already-compromised networks -- techniques Microsoft first documented in mid-August 2023 as used by the affiliate cluster Microsoft tracks as Storm-0875 (active with this build since July 2023).
The distinguishing behavior for this threat is Azure-specific: rather than only encrypting on-host filesystems, the attackers embedded a Base64-encoded Azure Storage account access key directly inside the ransomware binary, giving it standing authentication to Storage data-plane APIs independent of RBAC session tokens. Using that key (and, per Mitiga's parallel analysis, keys obtained via RBAC roles such as Storage Blob Data Contributor, Storage Blob Data Owner, and Storage Table Data Contributor, or any role holding the Microsoft.Storage/storageAccounts/listKeys/action permission), the ransomware mass-downloaded blob/table objects, encrypted them locally, and re-uploaded the encrypted copies, appending the .zk09cvt file extension. A second, related technique abused Azure Key Vault to generate encryption keys used for the operation and then deleted those keys afterward, denying the victim any path to recovery even if backups or blob versions existed. The Sophos-investigated incident encrypted 39 Azure Storage accounts. Detection-relevant precursor activity documented by Mitiga includes enabling public container access, disabling Blob Versioning, deleting blob versions prior to encryption, anomalous key-listing calls by users, and high-volume StorageRead operations immediately followed by StorageWrite operations.
BlackCat/ALPHV affiliates additionally relied on legitimate remote-monitoring-and-management (RMM) tools -- AnyDesk, Splashtop, and Atera -- for persistent access, and on the .NET exfiltration tool ExMatter (used exclusively by the Microsoft-tracked affiliate cluster DEV-0504, capable of self-deleting/'melting' after exfiltrating multi-terabyte volumes of data over SFTP and WebDAV) to support the group's double-extortion model, posting stolen data to a Tor-hosted dedicated leak site with a unique .onion access token per victim. Separately from this specific Sophos Central/Azure incident, the FBI/CISA/HHS joint #StopRansomware advisory AA23-353A (19 Dec 2023, revised 27 Feb 2024) documents the broader ALPHV affiliate ecosystem's TTPs -- Mimikatz and OS credential dumping from LSASS, Cobalt Strike Beacon and SystemBC/Coroxy for C2, Adfind and Nmap for AD/network reconnaissance, BITSAdmin for payload transfer, and vssadmin.exe/wevtutil.exe for shadow-copy deletion and event-log clearing -- and lists initial-access exploitation of CVE-2023-27532 (Veeam Backup & Replication), the ProxyShell Exchange chain (CVE-2021-34473/34523/31207), and Veritas Backup Exec vulnerabilities (CVE-2021-27876/27877/27878) by other ALPHV affiliates (e.g., UNC4466).
The same RaaS operation was behind the high-profile September 2023 MGM Resorts intrusion, in which the affiliate group Scattered Spider (UNC3944) identified an MGM employee via LinkedIn, impersonated them in a ten-minute vishing call to MGM's IT helpdesk, obtained Okta/Azure administrator access, and within days deployed ALPHV ransomware against more than 100 ESXi hypervisors alongside 6 TB of exfiltrated cus
Weaknesses (CWE)
CWE-798, CWE-522, CWE-306
Target sectors: cloud infrastructure, managed security service providers, hospitality, gaming casino, health, government administration, education, manufacturing, energy, financial services
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2023-27532, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2021-27876, CVE-2021-27877, CVE-2021-27878, T1598.004, T1589.003, T1583.004, T1588.002, T1190, T1078.004, T1199, T1059.001, T1047, T1078.004