A Gentlemen ransomware affiliate ran his own leak site and reached his victims through stolen CI/CD secrets, with attack commands driven through an MCP server (CloudSEK)
CloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove attacks over MCP
Analysis
CloudSEK reports that an exposed open directory and a misconfigured storage server revealed the operation of "Azazel", a Russian-speaking affiliate of the Gentlemen ransomware group, who used the group's tooling, negotiation channels and ransom-note template but published victims on a leak site of his own and kept the proceeds, so the Gentlemen operator lost the revenue (CloudSEK, 2026-10-05). Two servers held about 6 TB of stolen data from some two dozen victims, spanning logistics, insurance, pharmaceutical, AI, medical-device and government-adjacent organisations (CloudSEK, 2026-10-05).
Every victim outside one deeper intrusion was reached the same way: GitLab CI/CD variable stores and git history were mined for tokens, database credentials, API keys and SSH private keys with enumeration and secret-scanning tools, and one GitLab instance that served two unrelated organisations gave footholds at both (CloudSEK, 2026-10-05). From one CI/CD token the actor reached more than 150 databases, payment gateways and hundreds of source repositories across a SaaS platform and its clients, and at a platform hosting a government-linked financial registry it exfiltrated more than 120,000 records and then killed the PostgreSQL process and deleted the production data directory (CloudSEK, 2026-10-05). The deeper intrusion, into an AI platform, ran for weeks: an API that fetches user-supplied URLs server-side gave an unauthenticated route into the internal network, a recovered master key decrypted every secret in the cluster configuration, a hardcoded authentication-bypass token that had been removed from the code but stayed in git history gave lasting access, offline cracking was run against administrator hashes from the monitoring stack, and an object-storage bucket was mirrored continuously (CloudSEK, 2026-10-05). Ransom notes were pushed to eight surfaces, among them the login message, the SSH banner, a database configuration parameter, a database-admin login template, a repository README and an issue opened against the victim's project, and CloudSEK reports that the verification script drove these checks through an MCP server bound to a local port, an operational use of MCP as an attack execution channel of which CloudSEK has not identified earlier public reporting (CloudSEK, 2026-10-05).
Triage: legitimate backup jobs also mirror object storage to remote destinations, so the discriminator is the destination and the source host, not the copy command itself (CloudSEK, 2026-10-05).
Cited evidence
Every confirmed victim was reached through stolen CI/CD secrets.
Azazel registered a reverse shell handler as a tool inside an AI coding assistant via MCP, then drove attack execution through it.
Azazel recovered credentials from commits that appeared removed from the current branch.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.