Inside the Gentlemen Ransomware Affiliate’s Operation
Description
A Russian-speaking affiliate of the Gentlemen ransomware group, known as Azazel, operated a sophisticated ransomware and data exfiltration campaign targeting over two dozen organizations across six countries. Azazel exploited stolen CI/CD secrets, GitLab variable stores, and git history to gain initial access, and used novel techniques such as leveraging an AI coding assistant with a reverse shell over MCP as a command and control channel. The operation involved more than 50TB of dedicated bare-metal infrastructure and approximately 6TB of stolen data. Azazel ran an independent leak site to publish victim data and collect ransom payments, bypassing the main ransomware-as-a-service operator. The investigation uncovered active exfiltration during the analysis and detailed victim notification was conducted prior to public disclosure.
Reddit Discussion
New investigation from our team. An exposed open directory and a misconfigured storage server gave up the entire operation of a Gentlemen ransomware affiliate who calls himself Azazel.
The highlights:
- Every victim outside the big AI-company breach was reached through stolen CI/CD secrets, GitLab variable stores and git history. One GitLab instance was hosting pipelines for two unrelated orgs, so a single token got into both.
- He registered a reverse shell as a tool inside an AI coding assistant and drove attack execution through it over MCP (exec_in_session against a loopback-bound port). We couldn't find prior public reporting of MCP used operationally as a C2 channel in a live campaign. He was also scanning the internet for exposed MCP ports under the fingerprint "internet-census-mcp-scanner".
- 25+ orgs across six countries, 50TB+ of dedicated bare-metal infra, ~6TB of stolen data. One exfil job was still running while we were looking at it.
- The deep one was an AI company: SSRF through an unvalidated AI imaging API for initial access, then Jasypt bulk decryption, a JWT auth-bypass token pulled from git history, offline Grafana hash cracking, and a kubeconfig/SSH-key sweep across everything exfiltrated.
Full writeup with IOCs, a Sigma rule and mitigations:
https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat actor Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group, conducted a multi-faceted ransomware and data theft campaign. Using stolen CI/CD secrets from GitLab instances, including tokens that crossed organizational boundaries, Azazel gained access to victim networks. He registered a reverse shell as a tool inside an AI coding assistant and used the MCP protocol as a command and control channel, a novel operational technique not previously publicly reported. Azazel operated a three-node infrastructure: a victim-facing C2 and open directory server, a staging server with 29TB of storage for operational scripts and active exfiltration, and a long-term archive server with 22TB of stolen data. Victims spanned sectors including logistics, insurance, pharmaceuticals, AI, medical devices, and government-adjacent infrastructure. Azazel also ran his own leak site, LEAKNED, to publish stolen data and collect extortion payments independently of the main ransomware group, effectively betraying both victims and the ransomware operator. The investigation revealed active data exfiltration during the analysis and included coordinated victim notifications and TLP:RED disclosures.
Potential Impact
The operation resulted in the compromise of over two dozen organizations across six countries, with approximately 6TB of data stolen and more than 50TB of infrastructure dedicated to the attack and storage of stolen data. Victims included critical sectors such as AI companies, logistics, insurance, pharmaceuticals, and government-adjacent entities. The actor bypassed the ransomware group's revenue sharing by independently publishing victim data and collecting ransom payments. The use of stolen CI/CD secrets and GitLab tokens allowed broad lateral movement and access. The novel use of MCP as a C2 channel and AI assistant tooling demonstrates advanced operational capabilities. Active exfiltration was observed during the investigation, indicating ongoing risk to affected organizations.
Defensive Guidance
Coordinated victim notification was conducted prior to public disclosure, and TLP:RED technical details were shared with affected organizations. Organizations should review and rotate all CI/CD secrets, GitLab tokens, and related credentials to prevent unauthorized access. Monitoring for exposed or misconfigured storage servers and open directories is critical to avoid inadvertent data exposure. Given the novel use of MCP as a C2 channel, network defenders should consider monitoring and restricting MCP protocol traffic, especially on loopback and exposed ports. Since the threat actor exploited stolen secrets and misconfigurations, securing CI/CD pipelines and implementing strict access controls are recommended. No official patch or fix applies as this is an operational compromise scenario. Organizations should consult the detailed CloudSEK report and indicators of compromise for tailored detection and response.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:ransomware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["ransomware"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ac545f02cdf04f656d49a47
Added to database: 10/06/2026, 19:03:12 UTC
Last enriched: 10/06/2026, 19:03:19 UTC
Last updated: 10/07/2026, 03:18:12 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.