Gentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks
Gentlemen ransomware affiliate Azazel used Model Context Protocol as live command-and-control across victims in six countries.
CloudSEK reported that Russian-speaking Gentlemen affiliate Azazel used the Model Context Protocol to run commands during live intrusions, calling exec_in_session on an MCP service at 127.0.0.1:35367. He also ran LEAKNED, a leak site allegedly diverting extortion proceeds from the Gentlemen ransomware-as-a-service operation. Investigators found more than two dozen victim directories across six countries, including theft of over 120,000 records from a government-linked financial registry and deletion of its PostgreSQL data directory. Loot was staged on infrastructure exceeding 50TB combined and moved with aws s3 sync, scp, pg_dump, MinIO, and MEGA. CloudSEK called it confirmed MCP command abuse, not a new MCP software vulnerability.
- Azazel used MCP exec_in_session on localhost port 35367 as operational C2.
- LEAKNED leak site allegedly diverted Gentlemen RaaS extortion proceeds.
- More than two dozen victim directories spanned six countries and several sectors.
- A financial-registry breach stole over 120,000 records and deleted PostgreSQL data.
- Staging capacity exceeded 50TB, with MEGA as the final destination.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | forgitlab.com | 162.220.163[.]26 Threat actor owned GitLab hostname Domain forgitlab[.]com novostnik / LEAKNED IPv4 66.179.30[.]155 Note: IP address |
| ipv4 | 162.220.163.26 | 00 and an upload listener on port 9999. Staging occurred at 162.220.163.26, associated with forgitlab.com, while 66.179.30.155 hosted |
| ipv4 | 23.236.169.183 | ential-bearing container files. The exposed command server, 23.236.169.183, hosted directory listings on port 8000 and an upload liste |
| ipv4 | 66.179.30.155 | red at 162.220.163.26, associated with forgitlab.com, while 66.179.30.155 hosted publication and archival infrastructure. CloudSEK de |
Full article664 words · extracted from gbhackers.com · click to collapse
A Russian-speaking Gentlemen ransomware affiliate used the Model Context Protocol (MCP) to execute commands during live intrusions, turning an AI coding assistant’s tool interface into an operational command-and-control channel.
CloudSEK identified the activity while investigating exposed infrastructure belonging to an operator calling himself Azazel.
Azazel also operated LEAKNED, an independent leak site that allegedly diverted extortion proceeds away from the Gentlemen ransomware-as-a-service operation.
The strongest evidence appeared in va.py, a script that verified ransom-note placement across six internal hosts.
It invoked exec_in_session through an MCP service bound to 127.0.0.1:35367, authenticated with a fixed bearer token, and executed SSH-based verification commands inside the compromised environment.
Verification covered eight locations, including system login messages, home-directory ransom notes, SSH banners, PostgreSQL configuration, pgAdmin templates, and the victim’s GitLab repository and issue tracker.
The workflow demonstrates operational command execution rather than a theoretical prompt-injection scenario.
Azazel registered a reverse-shell handler as a tool accessible to an AI coding assistant.
Additional scripts, mcp_test.py and recon_mcp.py, indicated iterative development, while scanner logs carried the fingerprint “internet-census-mcp-scanner,” suggesting systematic reconnaissance for exposed MCP services.
CloudSEK described this as a confirmed instance of MCP exec_in_session abuse in a criminal campaign.
That finding should not be interpreted as proof that MCP itself was exploited through a newly discovered software vulnerability.
Earlier reporting also documented a Gentlemen affiliate operating a Penelope MCP interface, reinforcing the broader emergence of AI-connected tooling within ransomware intrusion workflows.

CloudSEK investigation uncovered, more than two dozen victim directories across six countries, affecting logistics, insurance, pharmaceuticals, artificial intelligence, medical devices, and government-adjacent infrastructure.
Most compromises followed a credential-harvesting chain targeting GitLab CI/CD variables and repository history.
Ransomware Affiliate Operations
Tools included glato, nord-stream, gitlab-secrets, gitlab-watchman, and gitleaks, enabling extraction of database passwords, API tokens, and SSH private keys.

One compromised GitLab instance exposed two unrelated organizations. Another SaaS intrusion reportedly expanded access to more than 150 databases, payment gateways, and hundreds of repositories across the provider and its customers.
In a government-linked financial registry breach, Azazel stole more than 120,000 records before terminating PostgreSQL and deleting its production data directory. These actions show destructive extortion extending beyond conventional file encryption.
A separate AI-platform compromise began through an inadequately validated server-side URL-fetching endpoint.
The attacker subsequently recovered a Jasypt master key, decrypted configuration secrets, retrieved an authentication-bypass token from Git history, and extracted Grafana password hashes for offline cracking.

Continuous object-storage synchronization remained active during the investigation, with stolen datasets growing by hundreds of gigabytes between observations.
Subsequent searches targeted Kubernetes configurations, SSH keys, and credential-bearing container files.
The exposed command server, 23.236.169.183, hosted directory listings on port 8000 and an upload listener on port 9999.
Staging occurred at 162.220.163.26, associated with forgitlab.com, while 66.179.30.155 hosted publication and archival infrastructure.
CloudSEK described a 29.2TB staging machine and a separate 22TB vault, exceeding 50TB combined capacity.
Transfers used aws s3 sync, scp, pg_dump, MinIO Client, and MEGAcmd, with MEGA serving as the final cloud destination.
Defenders should treat MCP execution tools as privileged interfaces, audit their invocation, restrict client identities, and avoid exposing services beyond loopback.
GitLab secret rotation must also cover repository history and downstream systems, not merely current pipeline variables.
CloudSEK said identified victims received coordinated notifications before publication, including restricted technical details for security contacts.
IOCs
| Indicator | Type | Value |
|---|---|---|
| C2 / open directory | IPv4 | 23.236.169[.]183 |
| forgitlab / loot repo | IPv4 | 162.220.163[.]26 |
| Threat actor owned GitLab hostname | Domain | forgitlab[.]com |
| novostnik / LEAKNED | IPv4 | 66.179.30[.]155 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.