Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks
Ransomware affiliate Azazel used an AI coding assistant's MCP tools to attack more than two dozen organizations.
CloudSEK reported that ransomware affiliate Azazel, working with the Gentlemen ransomware group, used an AI coding assistant as an intrusion channel against more than two dozen organizations in six countries, including logistics, insurance, pharmaceuticals, medical devices, and AI firms. Azazel registered a reverse-shell handler as an MCP tool and used it to run commands, including a script that verified ransom notes on internal hosts. Most access came from GitLab pipeline variables and repository history; one software provider breach reached more than 150 databases and over a dozen clients, and another victim lost more than 120,000 financial records before production data was deleted. A separate imaging-API attack stole more than 6TB, and Azazel ran an independent leak-and-extortion operation rather than sharing proceeds with Gentlemen.