CloudSEK Finds Gentlemen Ransomware Affiliate’s Exposed Servers and Stolen Data

· Original article ↗

Summary

CloudSEK reports that Gentlemen affiliate Azazel used stolen CI/CD secrets and other techniques to compromise more than two dozen organizations, steal about 6TB of data, and operate a separate extortion site. Exposed servers revealed the operation.

Key points

  • An exposed directory and misconfigured storage revealed Azazel’s three-node operation, which held more than 50TB of storage and approximately 6TB of stolen data from over two dozen organizations across six countries.
  • Azazel used Gentlemen ransomware tooling while operating the separate LEAKNED site and keeping extortion proceeds outside the group’s operation.
  • Most victims were accessed through credentials stolen from GitLab CI/CD variables and repository history; one GitLab instance provided access to two unrelated organizations.
  • A prolonged compromise of an AI platform began with an unauthenticated URL-fetching endpoint. Azazel then recovered encrypted configuration secrets and a JWT from Git history, cracked Grafana credentials, and continuously copied object-storage data.
  • CloudSEK found operational use of a local MCP server’s exec_in_session function to execute attack tasks, as well as scanning infrastructure searching for exposed MCP ports.
  • Data was staged across attacker-controlled infrastructure before transfer to MEGA; in one incident, the attacker reportedly deleted a production PostgreSQL data directory after exfiltration.
  • CloudSEK provided victims with technical notifications and published indicators, a Sigma detection rule, and mitigation guidance.

Article Details

Attack Vectors
  • Azazel harvested tokens, database credentials, API keys and SSH private keys from GitLab CI/CD variables and repository history. One compromised GitLab instance provided access to two unrelated organizations.
  • At an AI platform, Azazel exploited an AI medical imaging API that fetched user-supplied URLs without validation, providing unauthenticated access to internal services.
  • Azazel recovered a Jasypt master key to decrypt cluster configuration secrets and retrieved a removed authentication-bypass token from git history.
  • Azazel used a locally bound MCP server's exec_in_session function to run ransom-note verification checks across six victim hosts. The operation also scanned for exposed MCP server ports.
  • The reported exploitation arsenal included a PostgreSQL UDF, Redis SSH write, an OverlayFS SUID container-escape exploit and stolen SSH keys.
  • Data moved through a C2 upload listener and a dedicated staging server before transfer to MEGA. An incremental object-storage mirror was still transferring data during the investigation.
Defensive Notes
  • Store CI/CD credentials in a dedicated secrets manager; protect and rotate pipeline variables and tokens, and audit repository history for exposed secrets.
  • Restrict MCP servers to loopback, audit exec_in_session, and monitor MCP initialization requests from unapproved client identities.
  • Keep encryption keys and kubeconfig files separate from the configuration files they protect, and rotate cluster credentials if those files may have been exfiltrated.
  • Limit MinIO bucket access to least-privilege service accounts and monitor unexpected mc mirror or bulk-sync activity.
  • Protect monitoring databases and logs that may contain credentials. Keep backup credentials separate from production systems and test restoration.
  • Restrict PostgreSQL COPY TO PROGRAM and audit C extension loading. Alert on unusual CI/CD variable reads, service-account token use, and repository README or Issue changes.

Indicators of compromise

TypeIndicatorContext
DOMAINforgitlab[.]comThreat-actor-owned hostname associated with the operations staging server.
IPV4141[.]95[.]252[.]30Beacon check-in address listed in the article's indicators of compromise.
IPV4162[.]220[.]163[.]26Azazel's forgitlab operations staging server and stolen-data repository.
IPV423[.]236[.]169[.]183Azazel's victim-facing C2 server and exposed open directory; port 9999 received stolen data.
IPV466[.]179[.]30[.]155Azazel's novostnik server hosting the LEAKNED leak site and long-term archive.
IPV466[.]203[.]124[.]135Address identified as the MEGA cloud final exfiltration destination on port 443.

MITRE ATT&CK

T1021.004 · SSHAzazel used SSH access obtained through stolen keys and drove checks across six internal victim hosts.T1110.002 · Password CrackingAzazel extracted Grafana administrator hashes from exfiltrated monitoring database files and attempted offline cracking.T1190 · Exploit Public-Facing ApplicationAzazel used an AI medical imaging API's unvalidated server-side URL fetch to reach the victim's internal network.T1213.003 · Code RepositoriesAzazel mined git repository history for secrets, including a removed authentication-bypass token.T1485 · Data DestructionAfter exfiltration, Azazel ran a Python script that killed a live PostgreSQL process and deleted its production data directory.T1491.001 · Internal DefacementAzazel placed or checked ransom-note content across internal system messages, SSH and PostgreSQL banners, a pgAdmin login template, and a victim's GitLab README and Issue.T1530 · Data from Cloud StorageAzazel mirrored a victim's object-storage bucket, producing more than 6TB of exfiltrated data.T1552.001 · Credentials In FilesAzazel extracted credentials and tokens from GitLab CI/CD variables, repository history and cluster configuration files.T1552.004 · Private KeysAzazel obtained SSH private keys from CI/CD exposure and searched exfiltrated data for additional private keys.T1567.002 · Exfiltration to Cloud StorageAzazel transferred consolidated stolen data to MEGA cloud through mega-cmd-server.T1595 · Active ScanningThe operation conducted internet-wide scanning for exposed MCP server ports.

Threat Actors

Products

GitLabEvery confirmed victim was reached through stolen CI/CD secrets. A single compromised GitLab instance produced footholds at two unrelated organisations.GrafanaGrafana offline cracking. The monitoring stack's database files were inside the exfiltrated object storage. Azazel extracted admin hashes and ran offline cracking against them. The candidate list recovered from earlierJasyptCredential decryption. The platform encrypted credentials in cluster configuration files using Jasypt. Azazel recovered the master key and bulk-decrypted every protected value across the entire configuration set - everyJenkinsGitLab variable stores, Jenkins, git historyKubernetesKubernetes and infrastructure sweep. A dedicated script swept all 6.1TB of exfiltrated data for kubeconfig files, SSH private keys, and credential-bearing container configs - producing a complete exploitation blueprintMEGAMEGA cloud - 66.203.124.135:443. Final exfil destination. Data moved from victim networks to the C2 box, staged on forgitlab, then transferred to MEGA via mega-cmd-server. Three hops between victim and finalMicrosoft SQL ServerA publicly listed medical device manufacturer had a dedicated exfil script written specifically for their infrastructure, connecting directly to a Microsoft SQL Server instance and dumping every table to JSON.MinIOThe use of mc (MinIO Client) for object storage exfiltration, combined with MEGA for data transfer/storage, is consistent with the documented evolution of Gentlemen affiliate TTPs. Affiliates have adapted their toolingOdooand gitleaks for credential harvesting from repositories and variable stores, and brute_odoo.py for Odoo ERP brute forcing.pgAdminpgAdmin login template (login_user.html)PostgreSQLOne CI/CD token gave Azazel Oracle and PostgreSQL credentials, shipping API credentials, and SSH private keys for three separate cloud-hosted servers belonging to the second organisation.RedisPostgreSQL UDF + Redis SSH write

Tools

argocd_hunt.shStolen SSH keys, argocd_hunt.shbrute_odoo.pygitlab-watchman, and gitleaks for credential harvesting from repositories and variable stores, and brute_odoo.py for Odoo ERP brute forcing.check_rce_surface.shscan_vectors.py, sqli_hunt.py, deser_hunt.py, check_rce_surface.shdeser_hunt.pyscan_vectors.py, sqli_hunt.py, deser_hunt.py, check_rce_surface.shfind_full_token.shjasypt_decrypt_all.py, find_full_token.shgbasic_mirror_retry.shmc mirror, gbasic_mirror_retry.shgitlab-secretsCI/CD attack surfaces: glato for GitLab enumeration, nord-stream for cloud CI/CD secret extraction, gitlab-secrets, gitlab-watchman, and gitleaks for credential harvesting from repositories and variable stores, andgitlab-watchmanglato for GitLab enumeration, nord-stream for cloud CI/CD secret extraction, gitlab-secrets, gitlab-watchman, and gitleaks for credential harvesting from repositories and variable stores, and brute_odoo.py forgitleaksGitLab enumeration, nord-stream for cloud CI/CD secret extraction, gitlab-secrets, gitlab-watchman, and gitleaks for credential harvesting from repositories and variable stores, and brute_odoo.py for Odoo ERP bruteglatoAzazel's setup script installed a coherent toolkit oriented specifically at CI/CD attack surfaces: glato for GitLab enumeration, nord-stream for cloud CI/CD secret extraction, gitlab-secrets, gitlab-watchman,grafana_all.pygrafana_all.py, grafana_crack3.pygrafana_crack3.pygrafana_crack3.py, scan_vectors.pyjasypt_decrypt_all.pyjasypt_decrypt_all.py, find_full_token.shloki_analyze.pyloki_analyze.py, monitoring_grep.shmcThe use of mc (MinIO Client) for object storage exfiltration, combined with MEGA for data transfer/storage, is consistent with the documented evolution of Gentlemen affiliate TTPs. Affiliates have adapted their toolingmcp_test.pymcp_test.py and recon_mcp.py alongside va.py confirm this is developed, iterated tooling across multiple scripts - not a single discovery repurposed once.mega-cmd-serverData moved from victim networks to the C2 box, staged on forgitlab, then transferred to MEGA via mega-cmd-server. Three hops between victim and final destination: taking down any single node does not recover themonitoring_grep.shloki_analyze.py, monitoring_grep.shnord-streama coherent toolkit oriented specifically at CI/CD attack surfaces: glato for GitLab enumeration, nord-stream for cloud CI/CD secret extraction, gitlab-secrets, gitlab-watchman, and gitleaks for credentialPenelopethe operation. Port 9999 ran the HTTP upload listener receiving stolen data from victim networks. Penelope reverse shell sessions were handled here alongside the MCP C2 tooling.recon_mcp.pymcp_test.py and recon_mcp.py alongside va.py confirm this is developed, iterated tooling across multiple scripts - not a single discovery repurposed once.scan_vectors.pygrafana_crack3.py, scan_vectors.pysqli_hunt.pyscan_vectors.py, sqli_hunt.py, deser_hunt.py, check_rce_surface.shva.pyThe ransom note was assigned a unique tracking identifier embedded across every surface. va.py verified delivery across six internal hosts, checking eight surfaces in sequence:

Industries

Related Articles