CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Azazel

actor · actor:azazel single-source

Russian-speaking affiliate of the Gentlemen ransomware group that, per CloudSEK (2026-10-05), ran his own leak site alongside the program, reached victims through stolen CI/CD secrets and drove attack commands through an MCP server.

Aliases: LEAKNED operator

Coverage
1
first 2026-10-07 → last 2026-10-07
Latest activity
2026-10-07
CloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove attacks over MCP
Peak priority
notable
1 notable
Targets
technology
sectors: technology, healthcare, public-sector
Sources cited
1
1 hosts

Defender insights

What each entry about Azazel tells a defender to do, newest first.

2026-10-07NOTABLECloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove attacks over MCP

Exposure · triage · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-10-07A Gentlemen ransomware affiliate ran his own leak site and reached his victims through stolen CI/CD secrets, with attack commands driven through an MCP server (CloudSEK)
    active-threatsCloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove attacks over MCP
ATT&CK techniques (10 across 8 tactics)

10 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts · Exploit Public-Facing Application
  • PersistenceValid Accounts
  • Privilege EscalationValid Accounts
  • StealthValid Accounts
  • Credential AccessBrute Force: Password Cracking · Unsecured Credentials: Credentials In Files · Unsecured Credentials: Private Keys
  • CollectionData from Information Repositories: Code Repositories · Data from Cloud Storage
  • ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactData Destruction · Defacement: Internal Defacement

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Credential Access TA0006

T1110.002Brute Force: Password Cracking×1

Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained. OS Credential Dumping can be used to obtain password hashes, this may only get an adversary so far when Pass the Hash is not an option. Further, adversaries may leverage Data from Configuration Repository in order to obtain hashed credentials for network devices.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

T1491.001Defacement: Internal Defacement×1

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.

Evidence: 2026-10-07/gentlemen-affiliate-azazel-ci-cd-secrets-mcp-attacks · ATT&CK page ↗

Entries about Azazel (1)

2026-10-07 · view entry permalink →

NOTABLENATOB2

A Gentlemen ransomware affiliate ran his own leak site and reached his victims through stolen CI/CD secrets, with attack commands driven through an MCP server (CloudSEK)

CloudSEK reports that an exposed open directory and a misconfigured storage server revealed the operation of "Azazel", a Russian-speaking affiliate of the Gentlemen ransomware group, who used the group's tooling, negotiation channels and ransom-note template but published victims on a leak site of his own and kept the proceeds, so the Gentlemen operator lost the revenue (CloudSEK, 2026-10-05). Two servers held about 6 TB of stolen data from some two dozen victims, spanning logistics, insurance, pharmaceutical, AI, medical-device and government-adjacent organisations (CloudSEK, 2026-10-05).

Every victim outside one deeper intrusion was reached the same way: GitLab CI/CD variable stores and git history were mined for tokens, database credentials, API keys and SSH private keys with enumeration and secret-scanning tools, and one GitLab instance that served two unrelated organisations gave footholds at both (CloudSEK, 2026-10-05). From one CI/CD token the actor reached more than 150 databases, payment gateways and hundreds of source repositories across a SaaS platform and its clients, and at a platform hosting a government-linked financial registry it exfiltrated more than 120,000 records and then killed the PostgreSQL process and deleted the production data directory (CloudSEK, 2026-10-05). The deeper intrusion, into an AI platform, ran for weeks: an API that fetches user-supplied URLs server-side gave an unauthenticated route into the internal network, a recovered master key decrypted every secret in the cluster configuration, a hardcoded authentication-bypass token that had been removed from the code but stayed in git history gave lasting access, offline cracking was run against administrator hashes from the monitoring stack, and an object-storage bucket was mirrored continuously (CloudSEK, 2026-10-05). Ransom notes were pushed to eight surfaces, among them the login message, the SSH banner, a database configuration parameter, a database-admin login template, a repository README and an issue opened against the victim's project, and CloudSEK reports that the verification script drove these checks through an MCP server bound to a local port, an operational use of MCP as an attack execution channel of which CloudSEK has not identified earlier public reporting (CloudSEK, 2026-10-05).

Triage: legitimate backup jobs also mirror object storage to remote destinations, so the discriminator is the destination and the source host, not the copy command itself (CloudSEK, 2026-10-05).

Every confirmed victim was reached through stolen CI/CD secrets.

Azazel registered a reverse shell handler as a tool inside an AI coding assistant via MCP, then drove attack execution through it.

Azazel recovered credentials from commits that appeared removed from the current branch.

CloudSEK TRIAD 2026-10-05
threat07 Oct 04:46Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cloudsek.com1 (100%)