A Russian-speaking cybercriminal known as Azazel turned on his ransomware-as-a-service (RaaS) partners to steal the extorted funds from more than two dozen victims worldwide, according to CloudSEK’s new report, The Gentlemen Files, published on 5 October. Investigators uncovered two exposed servers run by Azazel, who operated under the Leakned brand to publish victim data and collect extortion proceeds independently of the Gentlemen group’s program.
The operation affected organisations across six countries in sectors including logistics, insurance, pharmaceuticals, AI, medical devices and government, with terabytes of data exfiltrated.
Azazel deployed two distinct attack chains. In the first, he harvested secrets from exposed GitLab infrastructure—CI/CD tokens, database credentials, API keys and SSH private keys—potentially preserved in earlier commits after developers purged current versions. These secrets provided access to cloud systems and databases.
In the second, he targeted a medical-imaging company by exploiting a server-side request forgery (SSRF) vulnerability in an unauthenticated AI medical-imaging API, enabling discovery of internal services and a sustained, multi-week compromise that led to the breach of 6TB of data.
Notably, Azazel reportedly used an AI coding assistant to issue commands to a compromised host via a reverse-shell handler linked to MCP, with the operator’s toolkit described as including chain-of-attack techniques such as Jasypt decryption, JWT recovery from git history, Grafana cracking, and Kubernetes kubeconfig harvesting. The operation allegedly maintained a 29TB staging server and a separate 22TB long-term vault, rather than relying on ephemeral cloud storage.