CloudSEK: Gentlemen ransomware affiliate "Azazel" breached more than two dozen organisations in six countries via stolen GitLab CI/CD secrets, ran commands through an AI assistant's MCP tool and kept the ransom for his own leak site
CloudSEK published research on 5 October 2026 on a Russian-speaking affiliate of the Gentlemen ransomware group who calls himself Azazel. An exposed open directory and a misconfigured storage server revealed more than two dozen victim directories and about 6TB of stolen data from organisations in logistics, insurance, pharmaceuticals, AI, medical devices and government-adjacent services across six countries (CloudSEK does not name them), with one exfiltration still running during the investigation. Most victims were reached the same way: tokens, database credentials, API keys and SSH keys harvested from GitLab CI/CD variables and git history. One CI/CD token at a SaaS provider reached more than 150 databases, payment gateways and hundreds of repositories across more than a dozen client companies; at a platform hosting a government-linked financial registry, more than 120,000 records were taken before the attacker killed the live PostgreSQL process and deleted the production data. A separate intrusion at an AI company began with an AI medical imaging API that fetched user-supplied URLs without validation (server-side request forgery). CloudSEK found a reverse-shell handler registered as a tool in an AI coding assistant through the Model Context Protocol (MCP), and a script that used that MCP channel to confirm ransom notes had landed on six internal hosts, which it calls the first public report of MCP used this way as a criminal control channel. Azazel published victims on his own leak site, LEAKNED, and did not share proceeds with the Gentlemen operator. CloudSEK says it notified identified victims before publication. Primary: CloudSEK; wire: Cyber Security News.
- Product
- GitLab CI/CD variables and repository history; AI coding assistant MCP tooling; AI inference API (SSRF)
- Versions
- n/a — intrusion campaign; no product CVE named
- Exploited in Australia?
- unknown
- Patch to
- Move pipeline secrets out of CI/CD variables and into a secrets manager, rotate any token that has ever sat in a variable or in git history, and scan history with a tool such as gitleaks. Bind MCP servers to localhost, log privileged tool calls, and alert on unusual pipeline-variable reads, service-account token use and bulk storage transfers. Validate URLs that AI or image APIs fetch server-side, and keep tested backups separate from production.
Primary: CloudSEK — Caught in 4K: The Gentlemen Files (5 Oct 2026) · Cyber Security News — Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks (6 Oct 2026)
