A ransomware affiliate who calls himself Azazel used The Gentlemen's tooling, negotiation channels and ransom note template to break into more than two dozen organizations across six countries, then published the stolen data on a leak site of his own and kept the proceeds, according to a new investigation by CloudSEK's TRIAD research team. The whole operation came to light because one of his servers left an unauthenticated file listing open on the internet.
Two servers held over two dozen victim directories and roughly 6TB of stolen data from logistics, insurance, pharmaceutical, AI, medical device and government-adjacent organizations. One exfiltration was still running while CloudSEK watched. CloudSEK says it notified the affected organizations before publishing.
A double-cross inside the affiliate model
Ransomware-as-a-service crews rent their malware and leak site to affiliates in exchange for a cut. Azazel skipped that step. None of the victims he compromised with Gentlemen tooling appeared on the gang's own leak site; they appeared instead on LEAKNED, an independent blog he ran from a server internally codenamed "novostnik", Russian for "newsman". The researchers assess Azazel as a Russian speaker, citing fluent Russian prose in his script comments.
Stolen pipeline secrets opened every door
Every confirmed victim outside one AI company was reached through stolen CI/CD secrets, the tokens and passwords that build pipelines use to deploy code. His toolkit, built around open-source tools such as glato, nord-stream and gitleaks, was made for exactly that. A single exposed GitLab instance hosted pipelines for two unrelated organizations, and one token yielded Oracle and PostgreSQL credentials plus SSH keys for three cloud servers belonging to the second.
The downstream damage was wide. From one CI/CD token at a SaaS platform, CloudSEK says Azazel reached more than 150 databases, payment gateways and hundreds of source code repositories across the platform and its clients. At a platform hosting a government-linked financial registry he took more than 120,000 records, then killed the live PostgreSQL process and deleted the production data directory.
The AI company was a different kind of intrusion: weeks of access that began with a medical imaging API fetching user-supplied URLs without validation and moved on through decrypted configuration secrets and a login token recovered from git history. More than 6TB from that one target was still syncing when the investigation found it.
An AI coding assistant as a command channel
CloudSEK found that Azazel registered a reverse shell handler as a tool inside an AI coding assistant through the Model Context Protocol (MCP), the standard that lets AI assistants call external tools. His script va.py used that channel to verify his ransom note had landed on eight surfaces across six internal hosts, including an issue opened in the victim's own GitLab project. He also ran internet-wide scanning for exposed MCP ports. CloudSEK says it has not found prior public reporting of a threat actor using MCP this way in a live criminal campaign.
Lock down CI/CD secrets and watch for bulk mirroring
CloudSEK's advice starts with the entry point: keep CI/CD credentials in a dedicated secrets manager rather than raw pipeline variables, mask and protect every variable, and rotate tokens on a fixed schedule. The report also ships a Sigma rule for MinIO Client mc mirror commands copying bucket contents to an external destination, a technique it ties to wider Gentlemen affiliate activity alongside MEGA as a final drop. Defenders tracking The Gentlemen will find the affiliate tradecraft consistent with earlier reporting on the crew's playbook.
Indicators (defanged):
- 23[.]236[.]169[.]183 (C2 and open directory)
- 162[.]220[.]163[.]26 and forgitlab[.]com (staging server)
- 66[.]179[.]30[.]155 (LEAKNED leak site and archive)
- 141[.]95[.]252[.]30 (beacon check-in)
- 66[.]203[.]124[.]135:443 (MEGA exfiltration endpoint)
The lesson cuts both ways: one leaked pipeline token can expose a whole client base, and the affiliates a ransomware gang arms can just as easily cut it out of the deal.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.