Cloud ransomware operators are shifting their focus from exploiting cloud service provider vulnerabilities to targeting web applications built with PHP.
Researchers have identified new ransomware scripts specifically designed to attack PHP applications, such as Pandora Script, IndoSec Group's Approach, and ShadowWeave Script.
Cybercriminals are leveraging cloud-native functions like Azure Storage Explorer, Amazon S3 storage, and FTP sites to exfiltrate stolen data.
Organizations should implement robust security measures, regularly update and patch web applications, monitor for unusual activities, and conduct vulnerability assessments to protect against these emerging cloud ransomware threats.