CloudSEK Links Gentlemen Affiliate Azazel to Leak Site and MCP Abuse
CloudSEK says Gentlemen affiliate Azazel kept extortion money via Leakned and abused an AI assistant’s MCP tools against more than 25 victims in six countries.
CloudSEK reporting dated 6 October 2026, covered by Infosecurity Magazine, GBHackers, and Cyber Security News, describes Russian-speaking Gentlemen ransomware-as-a-service affiliate Azazel running an independent leak site—spelled Leakned or LEAKNED—to publish stolen data and retain extortion proceeds instead of passing them to the RaaS operator. GBHackers alone calls the diversion alleged, while Cyber Security News says he worked with Gentlemen but did not share proceeds. The outlets agree on more than 25 victims, also phrased as more than two dozen organizations or directories, across six countries in logistics, insurance, pharmaceuticals, AI, medical devices, and government. Intrusions harvested CI/CD tokens, database credentials, API keys, and SSH keys from GitLab history and, according to Cyber Security News, pipeline variables; that outlet also reports one software-provider breach of more than 150 databases and over a dozen clients, imaging-API theft it puts above 6TB (Infosecurity says 6TB over weeks via SSRF), and more than 120,000 financial-registry records deleted along with a PostgreSQL data directory. Azazel linked an AI coding assistant to a reverse-shell handler through MCP—GBHackers cites exec_in_session on 127.0.0.1:35367—and used it for commands including a ransom-note check; CloudSEK treated this as command abuse, not a new MCP flaw. Storage was a 29TB staging server plus a 22TB vault, matching capacity above 50TB, with transfers via aws s3 sync, scp, pg_dump, MinIO, and MEGA.
- CloudSEK’s 6 October 2026 report, “The Gentlemen Files,” identifies Russian-speaking Gentlemen ransomware-as-a-service affiliate Azazel.
- He ran an independent leak site spelled Leakned or LEAKNED to publish victim data and keep extortion proceeds; only GBHackers calls that diversion alleged.
- Activity covered more than 25 victims—also described as more than two dozen organizations or directories—across six countries in logistics, insurance, pharmaceuticals, AI, medical devices, and government.
- Access used secrets from GitLab commit history and, per Cyber Security News, pipeline variables, including CI/CD tokens, database credentials, API keys, and SSH keys; one software-provider breach reached more than 150 databases and over a…
- SSRF in an unauthenticated AI medical-imaging API yielded 6TB, which Cyber Security News puts at more than 6TB; a government-linked financial registry lost over 120,000 records and had its PostgreSQL data directory deleted.
- An AI coding assistant was tied to a reverse-shell handler via MCP, including exec_in_session on 127.0.0.1:35367 and a ransom-note check; CloudSEK called it MCP command abuse, not a new MCP vulnerability.
- Loot was held on a 29TB staging server and a 22TB vault—combined capacity above 50TB—and moved with aws s3 sync, scp, pg_dump, MinIO, and MEGA.
- Cyber Security News says CloudSEK published attacker infrastructure, including IP addresses, forg gitlab.com, and MCP scripts.
Coverage timelineoldest first · each row is one article
- · 2d agoRansomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
Infosecurity Magazine· 65
CloudSEK exposes Gentlemen RaaS affiliate 'Azazel' who diverted extortion proceeds via his own Leakned leak site after compromising 25+ victims across six countries.
- · 2d agoGentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks
GBHackers· 78
Gentlemen ransomware affiliate Azazel used Model Context Protocol as live command-and-control across victims in six countries.
- · 2d agoRansomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks
Cyber Security News· 82