The Gentlemen Ransomware Affiliate Utilizes MCP in Multi-Sector Cyberattacks
Executive Summary On 5 October 2026, CloudSEK identified a Russian-speaking The Gentlemen ransomware affiliate who used the Model Context Protocol (MCP) to execute malicious commands during live intrusions, turning an AI coding assistant’s tool interface into an operational command-and-control channel. The operator, designating himself Azazel, also operated LEAKNED, an independent leak site that allegedly diverted…
Read More