# Azazel: Gentlemen Ransomware Affiliate Compromises 24+ Organizations via Stolen CI/CD Secrets, Abuses MCP as C2 and Runs LEAKNED Leak Site

> CloudSEK documents Azazel, a Russian-speaking Gentlemen ransomware affiliate who breached more than two dozen organisations in six countries, every one reached through stolen CI/CD secrets or credentials recovered from compromised platforms. He exfiltrated data through a three-hop chain (victim, C2, staging, MEGA), published victims on his own LEAKNED leak site, and used MCP exec_in_session as an operational C2 channel.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2928
- **ID:** TL-2026-2928
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Azazel
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CloudSEK's 'Caught in 4K: The Gentlemen Files' (2026-10-05) analyses infrastructure operated by 'Azazel', a Russian-speaking affiliate of the Gentlemen ransomware-as-a-service (RaaS) operation. Azazel used Gentlemen tooling and tradecraft but also ran an independent leak site, LEAKNED, publishing victims and keeping ransom proceeds without sharing revenue with the RaaS operator. CloudSEK reports more than two dozen victims across six countries in logistics, insurance, pharmaceuticals, AI/medical imaging, medical devices and government-adjacent sectors. Active exfiltration was still under way when the infrastructure was observed. Victims were notified under TLP:RED before publication.

Attack chain A (CI/CD secrets harvesting): the operator installed CI/CD and secrets-hunting tooling (glato, nord-stream, gitlab-secrets, gitlab-watchman, gitleaks, brute_odoo.py) and enumerated GitLab CI/CD variable stores and repository history. Recovered secrets included Oracle and PostgreSQL credentials, shipping API credentials and SSH private keys for cloud servers. A single GitLab instance hosted pipelines for two unrelated organisations, so one token compromised both plus three cloud-hosted servers. One SaaS-platform compromise extended to a dozen or more client companies from a single CI/CD token (150+ databases, payment gateways, hundreds of repositories). In a government-linked financial registry, 120,000+ records were deleted after exfiltration. A script, va.py, delivered ransom notes to eight surfaces on six internal hosts: /etc/motd, ATTENTION_SENSITIVE_INFORMATION.txt in /root and /home/ubuntu, the SSH banner via sshd_config, the PostgreSQL cluster_name parameter, the pgAdmin login template, a victim GitLab repository README, and a GitLab Issue opened with a pipeline token.

Attack chain B (deep compromise of an AI platform): initial access was an SSRF in an AI medical-imaging API that fetched user-supplied URLs server-side without validation, reaching internal service discovery, object storage, caching and monitoring. The operator recovered the master key for Jasypt-encrypted cluster configuration (jasypt_decrypt_all.py) and bulk-decrypted database passwords, API keys and service tokens. A hardcoded JWT authentication-bypass token, removed in a later commit but recoverable from git history, gave persistent authenticated access. Grafana admin hashes from an exfiltrated monitoring database were cracked offline (grafana_crack3.py). Object storage was continuously mirrored with the MinIO client (mc mirror, with retry logic), and scan_vectors.py swept about 6.1TB for kubeconfig files, SSH keys and credential-bearing container configs. Other tooling references PostgreSQL COPY TO PROGRAM, UDF/C-extension loading, Redis SSH-key write and an OverlayFS SUID container-escape exploit.

MCP abuse: CloudSEK documents one confirmed instance of the Model Context Protocol exec_in_session tool used as a C2/execution channel in a live criminal campaign. va.py issued exec_in_session calls to an MCP server on 127.0.0.1:35367 with a fixed bearer token; mcp_test.py and recon_mcp.py show iterative development; an 'internet-census-mcp-scanner' fingerprint performed internet-wide MCP port discovery; the MCP client identity 'hermes' was observed. Storage-server output was consistent with an agentic AI assistant answering infrastructure-planning questions.

Infrastructure (50TB+): 23.236.169.183 (open directory on 8000, upload listener on 9999, Penelope reverse-shell handler, MCP C2 tooling); 162.220.163.26 (hostname forgitlab / forgitlab.com, GitLab masquerade staging, ~6TB active across 24+ victim directories); 66.179.30.155 ('novostnik', LEAKNED frontend, evidence-badge store and ~22TB vault); 66.203.124.135:443 (MEGA, final destination through mega-cmd-server); 141.95.252.30 (beacon check-in). Exfiltration used aws s3 sync, scp, pg_dump, HTTP POST to port 9999 and custom per-victim dump scripts, consistent with the Gentlemen affiliate shift from Rclone to Restic to mc.

Context: Gentlemen is a human-operated RaaS that emerged in mid-2025, moved to an affiliate model in September 2025, advertises a 90% affiliate share, and uses a Go-based locker; its backend database and chats were leaked in May 2026. Initial access in the wider operation relies heavily on edge-device and stolen-credential access. No CVEs are cited in the CloudSEK report.

## MITRE ATT&CK

- T1595.002 Active Scanning: Vulnerability Scanning
- T1583.003 Virtual Private Server
- T1190 Exploit Public-Facing Application
- T1078.004 Valid Accounts: Cloud Accounts
- T1059.006 Command and Scripting Interpreter: Python
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1611 Escape to Host
- T1552.001 Unsecured Credentials: Credentials In Files
- T1552.004 Unsecured Credentials: Private Keys
- T1110.002 Brute Force: Password Cracking
- T1021.004 Remote Services: SSH
- T1213.003 Data from Information Repositories: Code Repositories
- T1530 Data from Cloud Storage
- T1074.002 Data Staged: Remote Data Staging
- T1071.001 Application Layer Protocol: Web Protocols
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1485 Data Destruction
- T1491.001 Defacement: Internal Defacement

## Sources

- [Caught in 4K: The Gentlemen Files (CloudSEK)](https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files)
- [Thus Spoke the Gentlemen (Check Point Research)](https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/)
- [When the Ransomware Gang Gets Hacked: What the Gentlemen Leak Reveals (Check Point)](https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/)
- [The Gentlemen Ransomware (Unit 42)](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware.md)
- [Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group's Rise (Security Affairs)](https://securityaffairs.com/193622/uncategorized/infostealers-ai-and-a-90-affiliate-cut-fuel-the-gentlemen-groups-rise.html)
- [The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat (Hive Pro)](https://www.hivepro.com/threat-advisory/the-gentlemen-ransomware-a-rapidly-scaling-raas-threat)
- [Gentlemen GentleKiller Clears Path to Encryption (BlackFog)](https://www.blackfog.com/gentlemen-gentlekiller-clears-path-to-encryption/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2928
