Threat reportRansomwareTL-2026-2928
Azazel: Gentlemen Ransomware Affiliate Compromises 24+ Organizations via Stolen CI/CD Secrets, Abuses MCP as C2 and Runs LEAKNED Leak Site
Azazel: Gentlemen Ransomware Affiliate Compromises 24+ (TL-2026-2928), also tracked as The Gentlemen Files, is a high-severity ransomware operation, first published 2026-10-05. It is attributed to Azazel with medium confidence, affects GitLab GitLab CI/CD (self-hosted, secrets in pipeline variables), maps to 18 MITRE ATT&CK techniques (T1021.004, T1059.004, T1059.006), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 1Azazel
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-2928
- Threat ID
- TL-2026-2928
- Also known as
- The Gentlemen Files, LEAKNED
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Azazel
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- logistics, insurance, pharmacy, health, medical-devices, artificial-intelligence, government administration, finance, software-saas
- Target regions
- Global (6 countries per CloudSEK), Middle East
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Azazel: Gentlemen Ransomware Affiliate Compromises 24+
Malware and tooling: Gentlemen ransomware, azazel, Penelope, glato, mega-cmd-server, nord-stream
How Azazel: Gentlemen Ransomware Affiliate Compromises 24+ works
CloudSEK documents Azazel, a Russian-speaking Gentlemen ransomware affiliate who breached more than two dozen organisations in six countries, every one reached through stolen CI/CD secrets or credentials recovered from compromised platforms. He exfiltrated data through a three-hop chain (victim, C2, staging, MEGA), published victims on his own LEAKNED leak site, and used MCP exec_in_session as an operational C2 channel.
CloudSEK's 'Caught in 4K: The Gentlemen Files' (2026-10-05) analyses infrastructure operated by 'Azazel', a Russian-speaking affiliate of the Gentlemen ransomware-as-a-service (RaaS) operation. Azazel used Gentlemen tooling and tradecraft but also ran an independent leak site, LEAKNED, publishing victims and keeping ransom proceeds without sharing revenue with the RaaS operator. CloudSEK reports more than two dozen victims across six countries in logistics, insurance, pharmaceuticals, AI/medical imaging, medical devices and government-adjacent sectors. Active exfiltration was still under way when the infrastructure was observed. Victims were notified under TLP:RED before publication.
Attack chain A (CI/CD secrets harvesting): the operator installed CI/CD and secrets-hunting tooling (glato, nord-stream, gitlab-secrets, gitlab-watchman, gitleaks, brute_odoo.py) and enumerated GitLab CI/CD variable stores and repository history. Recovered secrets included Oracle and PostgreSQL credentials, shipping API credentials and SSH private keys for cloud servers. A single GitLab instance hosted pipelines for two unrelated organisations, so one token compromised both plus three cloud-hosted servers. One SaaS-platform compromise extended to a dozen or more client companies from a single CI/CD token (150+ databases, payment gateways, hundreds of repositories). In a government-linked financial registry, 120,000+ records were deleted after exfiltration. A script, va.py, delivered ransom notes to eight surfaces on six internal hosts: /etc/motd, ATTENTION_SENSITIVE_INFORMATION.txt in /root and /home/ubuntu, the SSH banner via sshd_config, the PostgreSQL cluster_name parameter, the pgAdmin login template, a victim GitLab repository README, and a GitLab Issue opened with a pipeline token.
Attack chain B (deep compromise of an AI platform): initial access was an SSRF in an AI medical-imaging API that fetched user-supplied URLs server-side without validation, reaching internal service discovery, object storage, caching and monitoring. The operator recovered the master key for Jasypt-encrypted cluster configuration (jasypt_decrypt_all.py) and bulk-decrypted database passwords, API keys and service tokens. A hardcoded JWT authentication-bypass token, removed in a later commit but recoverable from git history, gave persistent authenticated access. Grafana admin hashes from an exfiltrated monitoring database were cracked offline (grafana_crack3.py). Object storage was continuously mirrored with the MinIO client (mc mirror, with retry logic), and scan_vectors.py swept about 6.1TB for kubeconfig files, SSH keys and credential-bearing container configs. Other tooling references PostgreSQL COPY TO PROGRAM, UDF/C-extension loading, Redis SSH-key write and an OverlayFS SUID container-escape exploit.
MCP abuse: CloudSEK documents one confirmed instance of the Model Context Protocol exec_in_session tool used as a C2/execution channel in a live criminal campaign. va.py issued exec_in_session calls to an MCP server on 127.0.0.1:35367 with a fixed bearer token; mcp_test.py and recon_mcp.py show iterative development; an 'internet-census-mcp-scanner' fingerprint performed internet-wide MCP port discovery; the MCP client identity 'hermes' was observed. Storage-server output was consistent with an agentic AI assistant answering infrastructure-planning questions.
Infrastructure (50TB+): 23.236.169.183 (open directory on 8000, upload listener on 9999, Penelope reverse-shell handler, MCP C2 tooling); 162.220.163.26 (hostname forgitlab / forgitlab.com, GitLab masquerade staging, ~6TB active across 24+ victim directories); 66.179.30.155 ('novostnik', LEAKNED frontend, evidence-badge store and ~22TB vault); 66.203.124.135:443 (MEGA, final destination through mega-cmd-server); 141.95.252.30 (beacon check-in). Exfiltration used aws s3 sync, scp, pg_dump, HTTP POST to port 9999 and custom per-victim dump scripts, consistent with the Gentlemen affiliate shift from Rclone to Restic to mc.
Context: Gentlemen is a human-operated RaaS that emerged in mid-2025, moved to an affiliate model in September 2025, advertises a 90% affiliate share, and uses a Go-based locker; its backend database and chats were leaked in May 2026. Initial access in the wider operation relies heavily on edge-device and stolen-credential access. No CVEs are cited in the CloudSEK report.
MITRE ATT&CK techniques used in TL-2026-2928
Lateral Movement
T1021.004 Remote Services: SSH
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Collection
T1074.002 Data Staged: Remote Data Staging; T1213.003 Data from Information Repositories: Code Repositories; T1530 Data from Cloud Storage
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application
Credential Access
T1110.002 Brute Force: Password Cracking; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys
Impact
T1485 Data Destruction; T1491.001 Defacement: Internal Defacement
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Development
T1583.003 Virtual Private Server
Reconnaissance
T1595.002 Active Scanning: Vulnerability Scanning
Privilege Escalation
Affected products and versions in Azazel: Gentlemen Ransomware Affiliate Compromises 24+
- GitLab — GitLab CI/CD (self-hosted, secrets in pipeline variables)
Vulnerable versions: Misconfiguration, not a version-specific flaw - Various — Cloud/SaaS platforms, PostgreSQL, MinIO, Grafana, Kubernetes, Jasypt-encrypted configs, MCP servers
Vulnerable versions: Misconfiguration and credential exposure
Remediation for Azazel: Gentlemen Ransomware Affiliate Compromises 24+
Immediate actions
- Block and hunt for 23.236.169.183, 162.220.163.26, 66.179.30.155, 141.95.252.30 and forgitlab.com in network and proxy logs
- Rotate all CI/CD variables, runner and pipeline tokens, SSH keys and cloud credentials reachable from GitLab; audit CI/CD variable reads from unexpected IPs
- Alert on MCP initialize RPCs from unapproved client identities such as 'hermes' and on the 'internet-census-mcp-scanner' fingerprint
- Review README or Issue modifications made by pipeline tokens and ransom-note artifacts (ATTENTION_SENSITIVE_INFORMATION.txt, altered /etc/motd, SSH banner, PostgreSQL cluster_name)
Workarounds
- Restrict egress to MEGA and unapproved object-storage endpoints from servers and CI runners
Longer-term hardening
- Move secrets from raw pipeline variables to a dedicated secrets manager; mask and protect every variable and rotate on a fixed cadence
- Scan git history for committed secrets and treat removed commits as exposed
- Bind MCP servers strictly to loopback and treat exec_in_session as a privileged, audited operation
- Do not treat Jasypt ENC() values as a security boundary; keep keys and kubeconfig in a secrets manager
- Restrict MinIO buckets to least-privilege service accounts and monitor mc mirror / bulk sync from unexpected sources
- Keep backup credentials on separate infrastructure and test restores; restrict PostgreSQL COPY TO PROGRAM and C-extension loading
- Validate SSRF-prone URL-fetching endpoints with allow-lists and block access to internal metadata and service endpoints
Weaknesses (CWE) in Azazel: Gentlemen Ransomware Affiliate Compromises 24+
Timeline of Azazel: Gentlemen Ransomware Affiliate Compromises 24+
- Gentlemen RaaS emerges (mid-2025) as a human-operated, Go-locker-based ransomware-as-a-service operation
- Gentlemen moves to an affiliate model advertising a 90% affiliate share of ransoms
- Gentlemen internal backend database and chats leaked after the administrator reports a hosting-provider compromise
- Gentlemen's claimed victim total reaches about 580 across 77 countries by one tracker's count
- CloudSEK publishes 'Caught in 4K: The Gentlemen Files' after TLP:RED notification of named victims
- CloudSEK observes Azazel's C2, staging and LEAKNED infrastructure with exfiltration to MEGA still active; 24+ victims across six countries identified
Sources cited for Azazel: Gentlemen Ransomware Affiliate Compromises 24+
- Caught in 4K: The Gentlemen Files (CloudSEK)
- Thus Spoke the Gentlemen (Check Point Research)
- When the Ransomware Gang Gets Hacked: What the Gentlemen Leak Reveals (Check Point)
- The Gentlemen Ransomware (Unit 42)
- Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group's Rise (Security Affairs)
- The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat (Hive Pro)
- Gentlemen GentleKiller Clears Path to Encryption (BlackFog)
Detection coverage for TL-2026-2928
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2928 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.