A Russian-speaking ransomware affiliate spent months breaching companies across six countries, then quietly betrayed the gang he worked for, running his own leak site on the side and publishing victims independently. A single exposed server gave up the whole operation, and a new investigation from CloudSEK’s threat intelligence team has now mapped it end to end.
Key highlights from the report:
- The betrayal. The actor, who calls himself Azazel, worked as an affiliate of the Gentlemen ransomware group, using its tooling, negotiation channels and ransom note template. At the same time he ran an independent leak site, LEAKNED, publishing victim data independently without routing it through the Gentlemen program. Victims were exposed to both. It is not a pattern seen often in the affiliate world.
- The scale. More than two dozen organisations across logistics, insurance, pharmaceutical, AI, medical devices and government-adjacent infrastructure, in six countries. The operator ran more than 50TB of dedicated physical servers, including a 22TB long-term vault built to retain loot across multiple campaigns, far larger than a typical affiliate setup.
- One way in. Every confirmed victim was reached through stolen CI/CD secrets. A single compromised GitLab instance produced footholds at two unrelated organisations, and one CI/CD token exposed more than 150 databases across a SaaS platform and its clients, according to the operator’s own published claims.
- A criminal first with AI tooling. Azazel registered a reverse shell as a callable tool inside an AI agent harness via the Model Context Protocol, and ran his attacks through it. CloudSEK found no prior public reporting of this technique outside this operation. He also built infrastructure to scan the internet for exposed AI assistant ports, and used an AI assistant to manage his own criminal infrastructure.
- A deeper second campaign. Against one AI company, he ran a sustained compromise that began with an unvalidated AI imaging API, then moved through bulk credential decryption, a JWT token recovered from git history, offline Grafana password cracking and a full Kubernetes sweep. More than 6TB was taken, and the transfer was still running when investigators found it, growing by hundreds of gigabytes between observations.
- Destruction after theft. In one case involving a government-linked financial registry, the actor exfiltrated more than 120,000 records, according to the operator’s own published claims, then deleted the victim’s live production database.
- Attribution signals. Multiple operational scripts contain fluent Russian prose, and the staging server was codenamed “novostnik”, Russian for “newsman”.
Before publication, CloudSEK coordinated notifications to identified organisations that had not yet appeared on the leak site and shared full technical details with each named victim’s security contact.
The investigation is part of CloudSEK’s ongoing series documenting exposed attacker infrastructure. The full report, with the indicators of compromise, a detection rule and mitigation guidance, is here:
https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
Hackers breached propulsion system of U.S.-bound oil supertanker
Posted in Commentary with tags Coast Gu, FBI on October 5, 2026 by itnerdThe FBI and The U.S.Coast Guard investigators found evidence that hackers gained access to the digital propulsion system of the VL Prosperity, a fully loaded oil supertanker bound for Galveston, Texas, according to Bloomberg.
The hackers had temporary access to the propulsion system as the vessel approached the Texas coast this summer. Investigators have not determined how the attackers gained access, how long they remained in the system, who was responsible or what ship functions they may have been capable of controlling.
The FBI and Coast Guard boarded the VL Prosperity in August after the vessel lost communications and authorities received indications that its network had been compromised. The agencies also boarded a second vessel in the Gulf of Mexico because of a suspected cyber threat. By September, U.S. agencies were tracking cyber threats involving nearly 20 vessels around the world and had requested advance notice if any planned to enter a U.S. port. The VL Prosperity remains anchored offshore Galveston as the investigation continues.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Access and control are separate findings, and the public evidence on VL Prosperity stops before engine control. If investigators can show that an intruder reached a write-capable propulsion controller and issued a valid command, this would be the first publicly documented, independently confirmed cyberattack against a commercial vessel’s propulsion controls. That is a much bigger claim than temporary access to a digital system.
“Bloomberg reports that investigators found temporary access to the tanker’s digital propulsion system. The public joint statement from the Federal Bureau of Investigation and U.S. Coast Guard says the agencies boarded the vessel to examine its information technology (IT) and operational technology (OT) systems after indications that its networks were compromised. It reports no operational disruption, vessel instability, physical danger to the crew, or environmental impact.
“That distinction matters because a propulsion-related bridge console, engineering workstation, machinery automation gateway, and engine controller are materially different findings. The U.S. Coast Guard’s 2019 response to a malware incident aboard a deep-draft vessel is the useful comparison. The malware seriously degraded the ship’s onboard computer network, but investigators found that essential vessel control systems were unaffected. Maersk made a similar distinction during the 2017 NotPetya attack, when its shore and terminal systems were disrupted while its vessels remained maneuverable.
“The closest publicly documented physical-control event was the 2013 University of Texas test that moved a yacht off course by spoofing the Global Positioning System (GPS) and inducing navigation corrections. The researchers did not control the engine. In 2025, French authorities investigated Remote Access Trojan (RAT) malware found on the Fantastic ferry, but the operator said the intrusion was neutralized without operational consequences.
“VL Prosperity could change that record. The decisive evidence is a forensic trail showing a write-capable session sent a valid command to the engine controller and that the controller accepted it. Until authorities produce that, call this a propulsion-access incident. The public record does not yet support a confirmed propulsion takeover.”
ㅤ
Damon Small, Board of Directors, Xcape, Inc.:
“The rapid escalation from a single novel maritime intrusion to federal tracking of nearly 20 compromised vessels globally directly threatens an already precarious global oil market, creating upward pressure on crude prices and downstream refined products. These supertankers operate as self-sufficient floating cities governed by complex operational technology (OT) systems that manage crew life support, navigation, and critical cargo onboarding and offboarding. Although threat actor attribution remains unconfirmed, the scale and sophistication strongly suggest coordinated state-sponsored activity targeting maritime OT.
“A widespread compromise across vessel networks could ground entire fleets or trigger catastrophic physical disruption at sea. To mitigate these systemic risks, asset owners must enforce rigorous physical and digital network segmentation between vessel bridge controls, satellite communications, and IT networks, while implementing unidirectional security gateways and mandatory anomaly monitoring across onboard industrial control systems.”
“Critical Takeaways
“Air-gapping vessel networks only works if you do not run an ethernet cable straight from the satellite dish to the propulsion engine.”
Ladies and gentlemen, we welcome you to your next high value target. The good thing is that many of the defensive strategies are pretty much the same. Therefore those should be employed ASAP.
Leave a comment »