A Gentleman ransomware affiliate who called himself Azazel hit more than two dozen organizations across six countries. He then published the stolen data on his own leak site, LEAKNED, and kept the extortion proceeds.
CloudSEK’s TRIAD team found the operation through an exposed open directory and published its findings on October 5, 2026, as part of its “Caught in 4K” series.
Azazel used Gentlemen’s tooling, negotiation channels, and a ransom note template. He then ran LEAKNED separately, so victims were exposed on both sites and the RaaS operator lost revenue. CloudSEK says none of the victims compromised with Gentlemen’s tooling appeared on the group’s own leak site.
Gentlemen Ransomware Affiliate Azazel Double-Crosses Gang
Several clues point to a Russian speaker. His handle echoes a character in Bulgakov’s The Master and Margarita. His scripts contain full Russian sentences in their comments, and he named his publication server “novostnik,” or “newsman.”

Azazel split his operation across three nodes:
- C2 and open directory (23.236.169.183): This box received uploads on port 9999 and handled Penelope reverse shells.
- “forgitlab” staging (162.220.163.26): This rented bare-metal machine has 29.2TB of raw storage and held about 6TB across more than two dozen victim directories. Its name imitates GitLab infrastructure.
- “novostnik” archive (66.179.30.155): It hosts the LEAKNED frontend and a 22TB long-term vault.
Data moved from victims to the C2 box, then to For GitLab, and finally to MEGA cloud. Because of those three hops, taking down one node would not recover the data. CloudSEK notes that most affiliates use temporary cloud storage or rented VPS nodes instead.
Every victim outside the AI engagement was reached through stolen CI/CD secrets. Azazel’s toolkit included glato, nord-stream, gitlab-secrets, gitlab-watchman and gitleaks. He also used a custom Odoo brute-forcer.
A single GitLab instance gave him footholds at two unrelated organizations. One token yielded Oracle and PostgreSQL credentials, shipping API credentials and SSH keys for three cloud servers.
One SaaS breach reached more than 150 databases, payment gateways and hundreds of source code repositories, including the platform’s clients.
In another case, a platform hosting a government-linked financial registry lost more than 120,000 records. Azazel then killed the live PostgreSQL process and deleted the production data directory.
The most sophisticated intrusion targeted an AI medical imaging company and ran for weeks. CloudSEK links it to more than 6TB of stolen data, some of it still transferring during the investigation.
- Entry: An imaging API fetched user-supplied URLs without validation, creating an unauthenticated server-side proxy into the internal network.
- Credentials: He recovered the Jasypt master key and decrypted every protected configuration value at once.
- Backdoor: He found a hardcoded JWT bypass token that had been deleted from the code but remained in git history.
- Cracking: He ran offline cracking against Grafana admin hashes from the exfiltrated storage.
- Sweep: He mirrored the object storage continuously and scanned the data for kubeconfig files and SSH keys.

CloudSEK says it found no earlier public report of a threat actor using MCP exec_in_session as a C2 channel in a live criminal campaign. The script va.py called a locally bound MCP server at 127.0.0.1:35367.
Through it, the script checked ransom note delivery across eight surfaces on six hosts, including /etc/motd, the SSH banner and a GitLab issue.
Beacon logs show internet-wide scanning under the fingerprint “internet-census-mcp-scanner,” which hunted for exposed MCP ports. Output on the storage server also suggests Azazel used an AI assistant to plan backups and disk throughput.
The case shows how fragile the affiliate model is, because trust between RaaS operators and affiliates is limited. It also shows that CI/CD variables and git history are high-value targets.
Defenders should rotate exposed tokens and scrub secrets from repository history. They should also validate server-side URL fetches and bind or authenticate MCP ports.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.