Executive Summary
On 5 October 2026, CloudSEK identified a Russian-speaking The Gentlemen ransomware affiliate who used the Model Context Protocol (MCP) to execute malicious commands during live intrusions, turning an AI coding assistant’s tool interface into an operational command-and-control channel. The operator, designating himself Azazel, also operated LEAKNED, an independent leak site that allegedly diverted extortion proceeds away from The Gentlemen ransomware-as-a-service operation. An exposed open directory and a misconfigured storage server revealed the complete operation, uncovering more than two dozen victim directories across six countries.
Key Takeaways
- CloudSEK identified the activity while investigating exposed infrastructure belonging to an operator calling himself Azazel, where an exposed open directory and a misconfigured storage server revealed the complete operation.
- The investigation traced 50TB of exposed infrastructure to uncover more than two dozen victim directories across six countries, affecting logistics, insurance, pharmaceuticals, artificial intelligence, medical devices, and government-adjacent infrastructure.
- Analysts observed that most compromises followed a credential-harvesting chain targeting GitLab CI/CD variables and repository history, while a separate AI-platform compromise began through an inadequately validated server-side URL-fetching endpoint.
- Continuous object-storage synchronization remained active during the investigation, with stolen datasets growing by hundreds of gigabytes between observations, leading CloudSEK to describe this as a confirmed instance of MCP exec_in_session abuse in a criminal campaign
- Defenders should treat MCP execution tools as privileged interfaces, audit their invocation, restrict client identities, and avoid exposing services beyond loopback. GitLab secret rotation must also cover repository history and downstream systems, not merely current pipeline variables.
Indicators of Compromise
CloudSEK has provided the following Indicators of Compromise associated with the Azazel campaign, which is provided below for RH-ISAC Core Member awareness.
Indicator |
Type |
Value |
C2 / open directory |
IPv4 |
23.236.169[.]183 |
forgitlab / loot repo |
IPv4 |
162.220.163[.]26 |
Threat actor owned GitLab hostname |
Domain |
forgitlab[.]com |
novostnik / LEAKNED |
IPv4 |
66.179.30[.]155 |