Caught in 4K: The Gentlemen Files

Caught in 4K: The Gentlemen Files
CloudSEK uncovered Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group, who used stolen CI/CD secrets and a separate AI-platform intrusion to compromise more than two dozen organizations and exfiltrate over 6TB of data. He also ran his own independent leak site, LEAKNED, bypassed the RaaS operator’s revenue stream, and used MCP-based tooling and internet-wide scanning to support the operation. #Gentlemen #LEAKNED #Azazel #MCP #GitLab

Keypoints

  • Azazel operated as a Gentlemen ransomware affiliate while simultaneously running his own leak site, LEAKNED, and keeping extortion proceeds for himself.
  • More than two dozen organizations across six countries were exposed, with roughly 6TB of stolen data found across the operator’s infrastructure.
  • Most victims were compromised through stolen CI/CD secrets, especially from GitLab instances, which yielded tokens, credentials, API keys, and SSH private keys.
  • A separate high-value AI platform breach involved SSRF, Jasypt key recovery, JWT reuse from git history, Grafana password cracking, and Kubernetes credential harvesting.
  • Azazel used MCP tooling in a confirmed live attack execution role, including exec_in_session against a locally bound server, and also ran internet-wide scans for exposed MCP ports.
  • The investigation exposed three-hop exfiltration paths using victim systems, a staging server, and MEGA cloud, along with dedicated physical storage exceeding 50TB.
  • Operational scripts contained Russian prose, and the staging server codename “novostnik” reinforced the operator’s Russian-speaking identity.

MITRE Techniques

  • [T1210] Exploitation of Remote Services – Used to gain footholds through exposed services and internal access paths, including the AI platform entry point and GitLab-derived compromise paths. [‘Azazel reached internal service discovery, object storage, caching infrastructure, and monitoring systems without further authentication.’]
  • [T1190] Exploit Public-Facing Application – Leveraged an unauthenticated proxy and exposed web-facing systems to enter the victim environment. [‘Entry was through an AI medical imaging API that fetches user-supplied URLs server-side without validation.’]
  • [T1552.001] Credentials in Files – Harvested secrets from Git repositories, CI/CD variables, configuration files, and git history. [‘GitLab CI/CD variable stores and git repository history became credential sources.’]
  • [T1528] Steal Application Access Token – Recovered and used CI/CD tokens and JWT bearer tokens to maintain access and pivot across systems. [‘One CI/CD token gave Azazel Oracle and PostgreSQL credentials…’]
  • [T1003] OS Credential Dumping – Extracted admin hashes and other credential material from monitoring databases and configuration artifacts. [‘Azazel extracted admin hashes and ran offline cracking against them.’]
  • [T1110.002] Password Cracking – Performed offline cracking of Grafana admin hashes to recover additional access material. [‘Azazel extracted admin hashes and ran offline cracking against them.’]
  • [T1059.006] Command and Scripting Interpreter: Python – Used Python scripts for exfiltration, validation, and destructive actions. [‘After exfiltration, Azazel ran a python script killing the live PostgreSQL process.’]
  • [T1059.004] Command and Scripting Interpreter: Unix Shell – Used shell scripts to manage operations, exfiltration, and validation across hosts. [‘Multiple shell scripts and Python files contain fluent Russian prose in their comments.’]
  • [T1105] Ingress Tool Transfer – Moved tools and staged data across victim, staging, and final storage systems during the campaign. [‘Data moved from victim networks to the C2 box, staged on forgitlab, then transferred to MEGA.’]
  • [T1021.004] Remote Services: SSH – Used SSH-based access and transfer for staging and session handling. [‘scp moved staged data to forgitlab’s /data directory.’]
  • [T1041] Exfiltration Over C2 Channel – Exfiltrated victim data to the command-and-control server before onward staging. [‘HTTP POST to port 9999 on the C2 box.’]
  • [T1530] Data from Cloud Storage Object – Mirrored cloud object storage buckets and exfiltrated their contents at scale. [‘Detected mc mirror commands exfiltrating object storage bucket contents to an external destination.’]
  • [T1567.002] Exfiltration to Cloud Storage – Sent final consolidated stolen data to MEGA cloud for long-term retention. [‘mega-cmd-server transferred the final consolidated set to MEGA cloud.’]
  • [T1106] Native API – Used exec_in_session via MCP to drive attack execution against internal hosts. [‘The script calls 127.0.0.1:35367… as part of the multi-surface defacement chain.’]
  • [T1046] Network Service Discovery – Conducted internet-wide scanning for exposed MCP assistant ports and victim services. [‘The beacon log shows internet-wide scanning under the fingerprint “internet-census-mcp-scanner”.’]
  • [T1018] Remote System Discovery – Enumerated internal hosts and services after initial access to map the target environment. [‘Azazel reached internal service discovery…’]
  • [T1078] Valid Accounts – Used stolen tokens, recovered secrets, and decrypted credentials to access systems as authorized users. [‘bulk-decrypted every protected value across the entire configuration set.’]
  • [T1213] Data from Information Repositories – Pulled data from Git history, source repositories, and configuration stores. [‘Azazel mined the log, recovered the token…’]
  • [T1485] Data Destruction – Destroyed production data after exfiltration to deepen impact and hinder recovery. [‘deleting the production data directory.’]

Indicators of Compromise

  • [IP addresses] Exposed infrastructure and exfiltration endpoints – 23.236.169.183, 162.220.163.26, and 66.179.30.155
  • [IP address and port] Final cloud exfil destination – 66.203.124.135:443
  • [Port] MCP execution channel endpoint – 127.0.0.1:35367
  • [Hostnames] Operator infrastructure hostnames – forgitlab, novostnik
  • [File names] Operational and validation scripts – va.py, mcp_test.py, recon_mcp.py, brute_odoo.py
  • [Domains / services] Cloud and storage tooling – mega-cmd-server, LEAKNED, MEGA
  • [Tools / binaries] Exfiltration and storage utilities – mc, gitleaks, gitlab-watchman, nord-stream, glato


Read more: https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files