Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
CloudSEK exposes Gentlemen RaaS affiliate 'Azazel' who diverted extortion proceeds via his own Leakned leak site after compromising 25+ victims across six countries.
CloudSEK's 'The Gentlemen Files' report details Russian-speaking affiliate Azazel, who built an independent leak site called Leakned to publish victim data and keep extortion proceeds without routing them through The Gentlemen RaaS program. Exposed servers held several terabytes stolen from logistics, insurance, pharmaceutical, AI, medical device, and government victims across six countries. Attack chains included harvesting CI/CD tokens, database credentials, API keys, and SSH keys from exposed GitLab commit history, and exploiting SSRF in an unauthenticated AI medical-imaging API to steal 6TB over a weeks-long intrusion. Azazel also connected an AI coding assistant to a reverse-shell handler via MCP to run commands on a victim host, and maintained a 29TB staging server plus a 22TB long-term vault.
- Affiliate ran independent 'Leakned' leak site to divert ransom proceeds from The Gentlemen RaaS operator.
- Exposed servers held terabytes stolen from 25+ victims across six countries, including government and medical.
- Chains abused GitLab commit history secrets and SSRF in an unauthenticated AI medical-imaging API.
- AI coding assistant linked to a reverse shell via MCP issued commands on compromised hosts.
Full article409 words · extracted from infosecurity-magazine.com · click to collapse
A Russian-speaking cybercriminal betrayed his ransomware-as-a-service (RaaS) partners to make off with funds extorted from over two dozen global victims, CloudSEK has revealed.
The threat intelligence specialist detailed the double cross in a new report, The Gentlemen Files, published on October 5.
They researchers found two exposed servers managed by “Azazel” – an affiliate of The Gentlemen RaaS outfit – containing several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device, and government victims across six countries.
“Azazel was not running a standard affiliate playbook,” the report revealed.
“He built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims.”
Read more on double-crossing cybercriminals: ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Azazel ran two very different attack chains, according to the report.
The first involved harvesting secrets from exposed GitLab infrastructure including CI/CD tokens, database credentials, API keys and SSH private keys. These provided access to cloud systems and databases.
It’s likely the secrets were deleted by their developers from the current version of Git repositories but remained in earlier commits, which Azazel found.
A Sophisticated Threat Actor
In another case, the hacker targeted a medical-imaging company by exploiting a server-side request forgery (SSRF) vulnerability in an unauthenticated AI medical-imaging API.
This allowed him to discover internal services, before he went searching for credentials to internal data stores, in a "sustained, multi-stage compromise that ran for weeks" and eventually led to the compromise of 6TB of data.
Interestingly, Azazel used an AI coding assistant in this attack to send commands to a compromised machine on the victim’s network. They did so by connecting the AI tool to a reverse-shell handler via MCP.
"The Chain B engagement – SSRF through an AI inference endpoint, Jasypt decryption, JWT recovery from git history, Grafana cracking, MinIO incremental sync, Kubernetes kubeconfig harvesting – reflects a skill level well above standard affiliate tradecraft,” the report claimed.
“The MCP tooling adds a further dimension: operational use against one victim cluster, global scanning infrastructure for exposed AI assistant ports, and confirmed use of AI tooling for the operator's own infrastructure management.”
Unusually, they also maintained a 29TB dedicated staging server connected to a separate 22TB long-term vault, rather than use temporary cloud storage or rented VPS nodes, which is what most Gentlemen affiliates do.