Executive Summary
CloudSEK identified an exposed infrastructure operation led by a Russian-speaking threat actor known as Azazel, a rogue affiliate of the Gentlemen ransomware group. Azazel compromised over two dozen organizations across six countries, including sectors such as AI, pharmaceuticals, and government infrastructure. The actor notably double-crossed the Gentlemen RaaS operator by publishing stolen data on his own independent leak site, LEAKNED, and bypassing the group's revenue-sharing model.
Technically, Azazel utilizes two primary attack chains. Chain A focuses on systematic CI/CD secrets harvesting via GitLab instances to gain cloud and database access. Chain B involves a sophisticated multi-stage compromise of a high-value AI platform using SSRF via AI inference endpoints and JWT recovery from Git history. A significant finding is the operational use of the Model Context Protocol (MCP) `exec_in_session` calls as a Command and Control (C2) channel for attack execution and ransom note verification.
The impact is severe, with over 50TB of raw storage identified across Azazel's infrastructure. The actor demonstrates high technical proficiency by utilizing AI assistants for infrastructure management and building dedicated internet-wide scanning tools to find exposed AI assistant ports. This activity represents a significant evolution in ransomware affiliate tradecraft and highlights the emerging risks of AI-integrated development tools in the threat landscape.
Key Details
Threat Name
Gentlemen Ransomware Azazel Operation
Affects
—
Adversary
Azazel Other Adversaries and Aliases: Gentlemen ransomware group
Malware/Tools
Gentlemen ransomware, Penelope, glato, nord-stream, gitleaks, Aurora ransomware, internet-census-mcp-scanner, brute_odoo.py
