Threat reportRansomwareTL-2026-2928

Azazel: Gentlemen Ransomware Affiliate Compromises 24+ Organizations via Stolen CI/CD Secrets, Abuses MCP as C2 and Runs LEAKNED Leak Site

highACTIVE

Azazel: Gentlemen Ransomware Affiliate Compromises 24+ (TL-2026-2928), also tracked as The Gentlemen Files, is a high-severity ransomware operation, first published 2026-10-05. It is attributed to Azazel with medium confidence, affects GitLab GitLab CI/CD (self-hosted, secrets in pipeline variables), maps to 18 MITRE ATT&CK techniques (T1021.004, T1059.004, T1059.006), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
1Azazel
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-2928

Threat ID
TL-2026-2928
Also known as
The Gentlemen Files, LEAKNED
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Azazel
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
logistics, insurance, pharmacy, health, medical-devices, artificial-intelligence, government administration, finance, software-saas
Target regions
Global (6 countries per CloudSEK), Middle East
Detection rules
9
Indicators of compromise
22

Malware and tooling in Azazel: Gentlemen Ransomware Affiliate Compromises 24+

Malware and tooling: Gentlemen ransomware, azazel, Penelope, glato, mega-cmd-server, nord-stream

How Azazel: Gentlemen Ransomware Affiliate Compromises 24+ works

CloudSEK documents Azazel, a Russian-speaking Gentlemen ransomware affiliate who breached more than two dozen organisations in six countries, every one reached through stolen CI/CD secrets or credentials recovered from compromised platforms. He exfiltrated data through a three-hop chain (victim, C2, staging, MEGA), published victims on his own LEAKNED leak site, and used MCP exec_in_session as an operational C2 channel.

CloudSEK's 'Caught in 4K: The Gentlemen Files' (2026-10-05) analyses infrastructure operated by 'Azazel', a Russian-speaking affiliate of the Gentlemen ransomware-as-a-service (RaaS) operation. Azazel used Gentlemen tooling and tradecraft but also ran an independent leak site, LEAKNED, publishing victims and keeping ransom proceeds without sharing revenue with the RaaS operator. CloudSEK reports more than two dozen victims across six countries in logistics, insurance, pharmaceuticals, AI/medical imaging, medical devices and government-adjacent sectors. Active exfiltration was still under way when the infrastructure was observed. Victims were notified under TLP:RED before publication.

Attack chain A (CI/CD secrets harvesting): the operator installed CI/CD and secrets-hunting tooling (glato, nord-stream, gitlab-secrets, gitlab-watchman, gitleaks, brute_odoo.py) and enumerated GitLab CI/CD variable stores and repository history. Recovered secrets included Oracle and PostgreSQL credentials, shipping API credentials and SSH private keys for cloud servers. A single GitLab instance hosted pipelines for two unrelated organisations, so one token compromised both plus three cloud-hosted servers. One SaaS-platform compromise extended to a dozen or more client companies from a single CI/CD token (150+ databases, payment gateways, hundreds of repositories). In a government-linked financial registry, 120,000+ records were deleted after exfiltration. A script, va.py, delivered ransom notes to eight surfaces on six internal hosts: /etc/motd, ATTENTION_SENSITIVE_INFORMATION.txt in /root and /home/ubuntu, the SSH banner via sshd_config, the PostgreSQL cluster_name parameter, the pgAdmin login template, a victim GitLab repository README, and a GitLab Issue opened with a pipeline token.

Attack chain B (deep compromise of an AI platform): initial access was an SSRF in an AI medical-imaging API that fetched user-supplied URLs server-side without validation, reaching internal service discovery, object storage, caching and monitoring. The operator recovered the master key for Jasypt-encrypted cluster configuration (jasypt_decrypt_all.py) and bulk-decrypted database passwords, API keys and service tokens. A hardcoded JWT authentication-bypass token, removed in a later commit but recoverable from git history, gave persistent authenticated access. Grafana admin hashes from an exfiltrated monitoring database were cracked offline (grafana_crack3.py). Object storage was continuously mirrored with the MinIO client (mc mirror, with retry logic), and scan_vectors.py swept about 6.1TB for kubeconfig files, SSH keys and credential-bearing container configs. Other tooling references PostgreSQL COPY TO PROGRAM, UDF/C-extension loading, Redis SSH-key write and an OverlayFS SUID container-escape exploit.

MCP abuse: CloudSEK documents one confirmed instance of the Model Context Protocol exec_in_session tool used as a C2/execution channel in a live criminal campaign. va.py issued exec_in_session calls to an MCP server on 127.0.0.1:35367 with a fixed bearer token; mcp_test.py and recon_mcp.py show iterative development; an 'internet-census-mcp-scanner' fingerprint performed internet-wide MCP port discovery; the MCP client identity 'hermes' was observed. Storage-server output was consistent with an agentic AI assistant answering infrastructure-planning questions.

Infrastructure (50TB+): 23.236.169.183 (open directory on 8000, upload listener on 9999, Penelope reverse-shell handler, MCP C2 tooling); 162.220.163.26 (hostname forgitlab / forgitlab.com, GitLab masquerade staging, ~6TB active across 24+ victim directories); 66.179.30.155 ('novostnik', LEAKNED frontend, evidence-badge store and ~22TB vault); 66.203.124.135:443 (MEGA, final destination through mega-cmd-server); 141.95.252.30 (beacon check-in). Exfiltration used aws s3 sync, scp, pg_dump, HTTP POST to port 9999 and custom per-victim dump scripts, consistent with the Gentlemen affiliate shift from Rclone to Restic to mc.

Context: Gentlemen is a human-operated RaaS that emerged in mid-2025, moved to an affiliate model in September 2025, advertises a 90% affiliate share, and uses a Go-based locker; its backend database and chats were leaked in May 2026. Initial access in the wider operation relies heavily on edge-device and stolen-credential access. No CVEs are cited in the CloudSEK report.

MITRE ATT&CK techniques used in TL-2026-2928

Lateral Movement

T1021.004 Remote Services: SSH

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Collection

T1074.002 Data Staged: Remote Data Staging; T1213.003 Data from Information Repositories: Code Repositories; T1530 Data from Cloud Storage

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1110.002 Brute Force: Password Cracking; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys

Impact

T1485 Data Destruction; T1491.001 Defacement: Internal Defacement

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Resource Development

T1583.003 Virtual Private Server

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Privilege Escalation

T1611 Escape to Host

Affected products and versions in Azazel: Gentlemen Ransomware Affiliate Compromises 24+

  • GitLab — GitLab CI/CD (self-hosted, secrets in pipeline variables)
    Vulnerable versions: Misconfiguration, not a version-specific flaw
  • Various — Cloud/SaaS platforms, PostgreSQL, MinIO, Grafana, Kubernetes, Jasypt-encrypted configs, MCP servers
    Vulnerable versions: Misconfiguration and credential exposure

Remediation for Azazel: Gentlemen Ransomware Affiliate Compromises 24+

Immediate actions

  • Block and hunt for 23.236.169.183, 162.220.163.26, 66.179.30.155, 141.95.252.30 and forgitlab.com in network and proxy logs
  • Rotate all CI/CD variables, runner and pipeline tokens, SSH keys and cloud credentials reachable from GitLab; audit CI/CD variable reads from unexpected IPs
  • Alert on MCP initialize RPCs from unapproved client identities such as 'hermes' and on the 'internet-census-mcp-scanner' fingerprint
  • Review README or Issue modifications made by pipeline tokens and ransom-note artifacts (ATTENTION_SENSITIVE_INFORMATION.txt, altered /etc/motd, SSH banner, PostgreSQL cluster_name)

Workarounds

  • Restrict egress to MEGA and unapproved object-storage endpoints from servers and CI runners

Longer-term hardening

  • Move secrets from raw pipeline variables to a dedicated secrets manager; mask and protect every variable and rotate on a fixed cadence
  • Scan git history for committed secrets and treat removed commits as exposed
  • Bind MCP servers strictly to loopback and treat exec_in_session as a privileged, audited operation
  • Do not treat Jasypt ENC() values as a security boundary; keep keys and kubeconfig in a secrets manager
  • Restrict MinIO buckets to least-privilege service accounts and monitor mc mirror / bulk sync from unexpected sources
  • Keep backup credentials on separate infrastructure and test restores; restrict PostgreSQL COPY TO PROGRAM and C-extension loading
  • Validate SSRF-prone URL-fetching endpoints with allow-lists and block access to internal metadata and service endpoints

Weaknesses (CWE) in Azazel: Gentlemen Ransomware Affiliate Compromises 24+

CWE-918, CWE-798, CWE-522

Timeline of Azazel: Gentlemen Ransomware Affiliate Compromises 24+

  • Gentlemen RaaS emerges (mid-2025) as a human-operated, Go-locker-based ransomware-as-a-service operation
  • Gentlemen moves to an affiliate model advertising a 90% affiliate share of ransoms
  • Gentlemen internal backend database and chats leaked after the administrator reports a hosting-provider compromise
  • Gentlemen's claimed victim total reaches about 580 across 77 countries by one tracker's count
  • CloudSEK publishes 'Caught in 4K: The Gentlemen Files' after TLP:RED notification of named victims
  • CloudSEK observes Azazel's C2, staging and LEAKNED infrastructure with exfiltration to MEGA still active; 24+ victims across six countries identified

Sources cited for Azazel: Gentlemen Ransomware Affiliate Compromises 24+

Detection coverage for TL-2026-2928

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2928 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats