Cloud ransomware attacks are becoming more common, with threat actors finding new ways to exploit large cloud storage services and exfiltrate data, according to a new report from cybersecurity firm SentinelOne.
According to the company’s State of Cloud Ransomware in 2024 report, threat researchers at SentinelOne have identified several new tools designed to target web servers with ransomware, but also saw a new trend in attackers using cloud based software to exfiltrate the data they’ve stolen.
Although cloud storage services like Amazon Web Services (AWS) and Microsoft Azure Blob Storage are built to safely handle and store large amounts of unstructured data, the researchers said that they have become attractive targets for cyber-attacks due to the number of organisations relying on them.
SentinelOne found that ransomware attackers are quickly finding and adapting their techniques in what has become a running battle with cloud service providers (CSPs).
One common method attackers use involves exploiting poorly secured Simple Storage Service (S3) buckets, with access gained through stolen credentials or misconfiguration.
Once inside, the threat actors create a new encryption key using AWS’s Key Management Service (KMS) to lock the data, then schedule the new key for deletion, giving the victim just seven days to respond before the attacker’s key, and potentially all of the victim’s data, is lost forever.
Notably, the seven-day window before deletion was first implemented by cloud providers themselves as a way to ensure data retention, but has been co-opted by threat actors as a new line of attack.
Aside from ransomware targeting cloud services, the study found that threat actors are turning to cloud services to hold the data they intend to ransom.
The study highlights several examples of ransomware actors, including those mimicking the notorious LockBit group, using tools like Azure Storage Explorer and Amazon’s S3 storage services to remove and hold stolen data.
SentinelLab, SentilOne’s threat intelligence arm, said it had identified a simple Python script designed to run on Windows systems that would allow attackers to exfiltrate files to the cloud and then encrypt the local versions, although stressed that this method hasn’t yet been observed in the wild.
Recommended reading
- NCSC Releases Cloud Management Security Guidance
- NCSC Issues Guidance for Securing Cloud-Hosted SCADA Systems
- Cloud Complexity and AI are Too Much for Traditional Security
“We recommend that all customers use a Cloud Security Posture Management (CSPM) solution to discover and assess cloud environments,” wrote Alex Delamotte, threat researcher at SentinelLabs and author of the study.
“Additionally, always enforce good identity management practices such as requiring MFA on all admin accounts, and deploy runtime protection against all cloud workloads and resources.”
SentinelLabs research backs up evidence from other security providers that shows cloud based threats are on the rise. In its annual assessment of cloud security, Thales recently found that protecting cloud environments is now the top security priority ahead of all other areas for IT professionals.





