A Russian-speaking affiliate of the Gentlemen ransomware-as-a-service operation used Model Context Protocol (MCP) to run commands during live intrusions, turning an AI coding assistant’s tool interface into a command-and-control channel. CloudSEK identified the activity on October 5, and an exposed server revealed more than two dozen victim directories across six countries.
How the Gentlemen Affiliate Azazel Turned MCP Into a Command Channel
CloudSEK’s research identifies the affiliate as “Azazel,” a Russian-speaking member of the Gentlemen ransomware-as-a-service operation. MCP is the protocol that lets AI coding assistants call tools. According to CloudSEK, Azazel used that tool interface to execute commands during live intrusions, which effectively converted the assistant’s interface into a command channel.
The va.py Script and the Local MCP Service on Port 35367
A script named va.py invoked exec_in_session through an MCP service listening on 127.0.0.1:35367, authenticating with a fixed bearer token. CloudSEK observed the script being used to verify that ransom notes had been placed across six hosts. The service runs on the local loopback address.
LEAKNED and the Diverted Extortion Proceeds
Azazel also ran LEAKNED, an independent leak site. According to CloudSEK, LEAKNED allegedly diverted extortion proceeds away from the Gentlemen RaaS operators. The allegation means that the affiliate operated a separate extortion outlet alongside its work under the Gentlemen name, and that the money collected through it did not go to the operation that supplied the ransomware. The research describes the diversion as alleged.
Credential Harvesting Against GitLab CI/CD Variables
The intrusions followed a credential-harvesting chain aimed at GitLab CI/CD variables and repository history. The tools named in the research are glato, nord-stream, gitlab-secrets, gitlab-watchman and gitleaks. Each targets secrets stored in GitLab pipelines or committed to repositories.
One SaaS Intrusion Expanded to More Than 150 Databases
One SaaS intrusion reportedly expanded access to more than 150 databases, payment gateways and hundreds of repositories. CloudSEK’s report does not name the company involved. The scale of that single intrusion shows how far access to CI/CD secrets can extend once an attacker holds them.
Exposed Command Servers Revealed 24 or More Victims
An exposed open directory and misconfigured storage on three command-and-control servers, with combined capacity above 50TB, revealed 24 or more victim directories. The victims span six countries and sectors including logistics, insurance, pharmaceuticals, AI platforms and medical devices. The report does not name any of the victims.
Exfiltration Through aws s3 sync, scp, pg_dump and MEGA
The data theft used aws s3 sync, scp, pg_dump and MEGA. Between them these cover cloud storage synchronization, remote file copy, database dumps and a file-sharing service, which matches the mix of stolen data types that the victim directories held.
Timing and Scope of the Findings
CloudSEK’s report does not give exact intrusion dates. The discovery and reporting date of October 5 is the date used here. The findings document two dozen victims in six countries, and the full scope beyond the exposed directories has not been established.
The research shows a ransomware affiliate adopting an AI tooling interface during live attacks, an approach that put a command channel inside a protocol designed for AI coding assistants. CloudSEK published the findings as research, and no victims have been publicly named.
CloudSEK’s findings come from an exposed open directory and misconfigured storage on three command-and-control servers. The exposure let the firm document how Azazel ran live intrusions, including the use of MCP to verify ransom-note placement across six hosts. The affiliate’s use of the five named GitLab credential-harvesting tools and four exfiltration methods appears in the same research, alongside the leak-site activity described above and the 24 or more victim directories.
