Azazel Ransomware Operation and MCP Abuse
Score: 9/10

Azazel Ransomware Operation and MCP Abuse

Russian-speaking threat actor Azazel, an affiliate of the Gentlemen ransomware group, utilizes stolen CI/CD secrets and novel MCP-based C2 channels to target global sectors and host stolen data on an independent leak site, LEAKNED.

Executive Summary

CloudSEK identified an exposed infrastructure operation led by a Russian-speaking threat actor known as Azazel, a rogue affiliate of the Gentlemen ransomware group. Azazel compromised over two dozen organizations across six countries, including sectors such as AI, pharmaceuticals, and government infrastructure. The actor notably double-crossed the Gentlemen RaaS operator by publishing stolen data on his own independent leak site, LEAKNED, and bypassing the group's revenue-sharing model.

Technically, Azazel utilizes two primary attack chains. Chain A focuses on systematic CI/CD secrets harvesting via GitLab instances to gain cloud and database access. Chain B involves a sophisticated multi-stage compromise of a high-value AI platform using SSRF via AI inference endpoints and JWT recovery from Git history. A significant finding is the operational use of the Model Context Protocol (MCP) `exec_in_session` calls as a Command and Control (C2) channel for attack execution and ransom note verification.

The impact is severe, with over 50TB of raw storage identified across Azazel's infrastructure. The actor demonstrates high technical proficiency by utilizing AI assistants for infrastructure management and building dedicated internet-wide scanning tools to find exposed AI assistant ports. This activity represents a significant evolution in ransomware affiliate tradecraft and highlights the emerging risks of AI-integrated development tools in the threat landscape.

Key Details

Threat Name

Gentlemen Ransomware Azazel Operation

Affects

—

Adversary

Azazel Other Adversaries and Aliases: Gentlemen ransomware group

Malware/Tools

Gentlemen ransomware, Penelope, glato, nord-stream, gitleaks, Aurora ransomware, internet-census-mcp-scanner, brute_odoo.py

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance8
Enterprise Relevance10
Clarity & Structure7
Technical Depth9

Sources