CloudSEK has published an investigation into an affiliate of The Gentlemen ransomware operation, who used the handle Azazel. The report is titled Caught in 4K: The Gentlemen Files, and the title is earned — the researchers got their view because the operator left an open directory with an unauthenticated file listing on his own staging server.

Two things in it are worth separating. One is a technical first. The other is a story about crime economics.

MCP as the command channel

Model Context Protocol is the interface that lets an AI assistant call tools — run a command, read a file, query a service. It exists so an assistant can act rather than only answer.

Azazel wired it into the attack chain. CloudSEK describes a script that made authenticated calls to a local MCP endpoint using a fixed bearer token, invoking the protocol's session-execution function to run checks across six internal hosts inside a victim network. The researchers call this the confirmed operational use of MCP as an attack execution channel.

What makes this more than a curiosity is the second half. Azazel built dedicated internet-wide scanning infrastructure, under its own scanner fingerprint, hunting for exposed MCP server ports globally — and CloudSEK says he treated them as a general-purpose initial access vector, independent of the credential chain that opened everything else.

That is the part to take seriously. Not that an attacker used an AI tool, which is unremarkable by now, but that the tool interface itself is being swept for as an exposed service in its own right. MCP endpoints are a new category of thing that answers on a port, and they are being catalogued by someone who is not a researcher.

There is also a smaller detail with a long shadow: the staged output includes responses consistent with an AI assistant answering infrastructure planning questions — backup capacity, disk throughput, scan performance over large datasets. He was using it to run his own operation, not only his victims'.

We wrote last week about the question of who checks the badge when a model is told to refuse less for verified defenders. This is the other end of the same problem: the assistant here was not persuaded to do anything. It was handed a tool interface and used as plumbing.

Every victim came through a pipeline

For all the novelty above, the way in was ordinary and should be the part that worries most readers.

Every confirmed victim outside the AI sector was reached through GitLab CI/CD variable stores and git repository history. Not phishing. Not a perimeter exploit. Secrets that were sitting in the place teams put secrets.

A single exposed GitLab instance hosted pipelines for two unrelated organisations, and yielded Oracle and PostgreSQL credentials, shipping API credentials, and SSH private keys for three separate cloud-hosted servers. One instance, two companies, three servers.

The high-value target in the AI sector was reached differently: through an AI medical imaging API that fetched user-supplied URLs server-side without validating them, giving server-side request forgery into the internal network. A feature that retrieves a URL on the server's behalf is a doorway, and it keeps being built without one.

What a CI/CD token is worth

The cascade numbers are the argument for treating pipeline secrets as crown jewels.

One compromised SaaS platform extended to more than a dozen of that platform's own client companies. CloudSEK reports a single CI/CD token that reached more than 150 databases, payment gateways and hundreds of source code repositories. A government-linked financial registry lost more than 120,000 records.

In total: more than two dozen organisations across six countries — logistics, insurance, pharmaceuticals, medical devices, AI and government-adjacent infrastructure. Roughly 6TB of stolen data was staged across two dozen victim directories, with the AI target alone exceeding 6TB and still growing by hundreds of gigabytes between observations. The operator's own storage, across a staging server and an archive box, came to more than 50TB.

The affiliate robbed the gang

The second story is about money, and it is unusual.

Azazel operated as a Gentlemen affiliate, using the group's tooling. He also ran his own leak site, and that is where his victims appeared. CloudSEK is direct about the consequence: none of the victims he compromised using Gentlemen's tooling showed up on the Gentlemen group's own leak site. They showed up on his.

The extortion proceeds did not go back to the ransomware-as-a-service operator. The report notes this is not a common pattern in the affiliate ecosystem, and it is worth understanding why it matters. RaaS works because affiliates accept a revenue split in exchange for tooling and a brand. An affiliate who takes the tooling and keeps the money is a defection against the business model, not against the victims.

For defenders it has a practical edge: the absence of an organisation from a known group's leak site is not evidence it was not hit by that group's tooling.

Attribution

CloudSEK points to a Russian-speaking operator, on evidence that is more careful than usual — not borrowed words but, in its description, fluent Russian prose in script comments, full grammatical sentences. Infrastructure naming supports it: one server is named with a colloquial Russian word for newsman. The handle Azazel is a character from Bulgakov's The Master and Margarita.

What to do

  • Treat CI/CD variable stores and git history as the credential store they are. Rotate what is in them, and check whether a single instance serves more than one organisation.
  • Audit any API that fetches a user-supplied URL server-side. That is the pattern that opened the highest-value victim here.
  • Find out whether you are exposing an MCP endpoint to the internet, deliberately or otherwise. Somebody is scanning for them at internet scale.
  • Treat an assistant's tool interface as a privileged execution path, with the authentication and logging you would give a remote shell, because that is what it is.

What is not established

  • Which AI assistant or client was wired to the MCP endpoint. The report describes the protocol and the call, not the product.
  • The dates and duration of the campaign. CloudSEK's report does not give an operational timeline.
  • Whether any victim paid, and how much.
  • Whether The Gentlemen operators knew about LEAKNED, and what followed if they did.
  • The identities behind the handle. The language evidence points to a region, not a person.