A Russian-speaking ransomware affiliate spent months breaching companies across six countries, then quietly betrayed the gang he worked for, running his own leak site on the side and publishing victims independently. A single exposed server gave up the whole operation, and a new investigation from CloudSEK’s threat intelligence team has now mapped it end to end.
Key highlights from the report:
- The betrayal. The actor, who calls himself Azazel, worked as an affiliate of the Gentlemen ransomware group, using its tooling, negotiation channels and ransom note template. At the same time he ran an independent leak site, LEAKNED, publishing victim data independently without routing it through the Gentlemen program. Victims were exposed to both. It is not a pattern seen often in the affiliate world.
- The scale. More than two dozen organisations across logistics, insurance, pharmaceutical, AI, medical devices and government-adjacent infrastructure, in six countries. The operator ran more than 50TB of dedicated physical servers, including a 22TB long-term vault built to retain loot across multiple campaigns, far larger than a typical affiliate setup.
- One way in. Every confirmed victim was reached through stolen CI/CD secrets. A single compromised GitLab instance produced footholds at two unrelated organisations, and one CI/CD token exposed more than 150 databases across a SaaS platform and its clients, according to the operator’s own published claims.
- A criminal first with AI tooling. Azazel registered a reverse shell as a callable tool inside an AI agent harness via the Model Context Protocol, and ran his attacks through it. CloudSEK found no prior public reporting of this technique outside this operation. He also built infrastructure to scan the internet for exposed AI assistant ports, and used an AI assistant to manage his own criminal infrastructure.
- A deeper second campaign. Against one AI company, he ran a sustained compromise that began with an unvalidated AI imaging API, then moved through bulk credential decryption, a JWT token recovered from git history, offline Grafana password cracking and a full Kubernetes sweep. More than 6TB was taken, and the transfer was still running when investigators found it, growing by hundreds of gigabytes between observations.
- Destruction after theft. In one case involving a government-linked financial registry, the actor exfiltrated more than 120,000 records, according to the operator’s own published claims, then deleted the victim’s live production database.
- Attribution signals. Multiple operational scripts contain fluent Russian prose, and the staging server was codenamed “novostnik”, Russian for “newsman”.
Before publication, CloudSEK coordinated notifications to identified organisations that had not yet appeared on the leak site and shared full technical details with each named victim’s security contact.
The investigation is part of CloudSEK’s ongoing series documenting exposed attacker infrastructure. The full report, with the indicators of compromise, a detection rule and mitigation guidance, is here:
https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
Related
This entry was posted on October 5, 2026 at 11:29 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Inside a 50TB ransomware operation exposed by one open server
A Russian-speaking ransomware affiliate spent months breaching companies across six countries, then quietly betrayed the gang he worked for, running his own leak site on the side and publishing victims independently. A single exposed server gave up the whole operation, and a new investigation from CloudSEK’s threat intelligence team has now mapped it end to end.
Key highlights from the report:
Before publication, CloudSEK coordinated notifications to identified organisations that had not yet appeared on the leak site and shared full technical details with each named victim’s security contact.
The investigation is part of CloudSEK’s ongoing series documenting exposed attacker infrastructure. The full report, with the indicators of compromise, a detection rule and mitigation guidance, is here:
https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
Share this:
Like this:
Related
This entry was posted on October 5, 2026 at 11:29 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.