Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Affiliate Betrays Partners, Siphons Victim Funds

Cramped, dimly lit room with laptop, papers, and takeout containers, overlooking cityscape through grimy window.

"Azazel was not running a standard affiliate playbook," the CloudSEK report bluntly observed.

Azazel, Leakned, and the betrayal of The Gentlemen RaaS

CloudSEK disclosed in a report titled The Gentlemen Files, published on October 5, that a Russian‑speaking cybercriminal known as "Azazel" broke the expected rules of ransomware-as-a-service (RaaS) partnerships. Rather than routing stolen data and extortion payments back through the operator of The Gentlemen RaaS, Azazel "built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims," the report said.

Chain A: GitLab history and harvested secrets

One of Azazel’s methods was straightforward and surgical: searching exposed GitLab infrastructure for sensitive items left in earlier commits. CloudSEK reported that these included "CI/CD tokens, database credentials, API keys and SSH private keys," artifacts that provided access to cloud systems and databases. The report notes it’s likely those secrets "were deleted by their developers from the current version of Git repositories but remained in earlier commits, which Azazel found." That classic exposure-in-history pattern enabled lateral access without exotic zero‑day exploits.

Chain B: SSRF against an unauthenticated AI medical‑imaging API and a sustained multi‑stage compromise

In a contrasting engagement described as a "sustained, multi-stage compromise that ran for weeks," Azazel exploited a server-side request forgery (SSRF) vulnerability in an unauthenticated AI medical‑imaging API. The SSRF allowed discovery of internal services and led the attacker to search for credentials to internal data stores, ultimately compromising 6TB of data from the medical‑imaging company.

CloudSEK summarized the sophistication with a list of components: "The Chain B engagement – SSRF through an AI inference endpoint, Jasypt decryption, JWT recovery from git history, Grafana cracking, MinIO incremental sync, Kubernetes kubeconfig harvesting – reflects a skill level well above standard affiliate tradecraft.” That inventory shows multiple tooling and configuration targets spanning credential recovery, monitoring dashboards, object storage, and orchestration credentials.

AI tooling, MCP, and operational-scale scanning

Azazel’s tradecraft included operational uses of AI and orchestration tooling. CloudSEK reported that the attacker "used an AI coding assistant in this attack to send commands to a compromised machine on the victim’s network. They did so by connecting the AI tool to a reverse‑shell handler via MCP." The report added that "The MCP tooling adds a further dimension: operational use against one victim cluster, global scanning infrastructure for exposed AI assistant ports, and confirmed use of AI tooling for the operator's own infrastructure management."

In short, the operator combined an AI assistant with a reverse‑shell handler and global scanning to both scale discovery and automate aspects of infrastructure management — a mix that CloudSEK characterized as beyond standard affiliate tradecraft.

Data hoards, exposed servers, and the range of victims

CloudSEK located two exposed servers managed by Azazel that contained "several terabytes of data" stolen from victims in logistics, insurance, pharmaceutical, AI, medical device, and government sectors across six countries. In addition to those exposed servers, the report noted Azazel "maintained a 29TB dedicated staging server connected to a separate 22TB long‑term vault," an unusual choice compared with the temporary cloud storage or rented VPS nodes commonly used by other Gentlemen affiliates.

The combination of immediate exposure and large, persistent storage suggests the operator retained long‑term archives of stolen material as well as more active staging infrastructure for incremental syncs and exfiltration workflows.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: The report’s specifics — JWT recovery from git history, Grafana cracking, MinIO incremental sync, kubeconfig harvesting, and exposed AI assistant ports — point to concrete defensive checks. Teams will watch for leaked credentials in repository history, secure Grafana/MinIO endpoints, and monitor for anomalous scanning or reverse‑shell connections tied to AI assistant ports.
  • Policymakers and regulators: CloudSEK’s finding that an affiliate can operate an independent leak site (Leakned) and "collect extortion proceeds without routing them through the Gentlemen program" underscores how extortion economics can be fragmented. Regulators tracking ransomware payments, leak-site takedowns, or rules for disclosure may find the separation of affiliate and operator revenue streams relevant.
  • Affected enterprises (logistics, insurance, pharmaceutical, AI, medical device, and government): The range of targeted sectors and the use of both simple (git history) and complex (SSRF against AI inference endpoints) techniques indicates that attackers will exploit both developer mistakes and unauthenticated AI‑enabled services. These organizations will particularly note the reported 6TB compromise and the practice of maintaining large long‑term vaults of stolen data.

CloudSEK’s account closes with a clear image: a capable affiliate, operating outside normal RaaS channels, who combined repository‑forensic techniques, SSRF against AI endpoints, and AI‑assisted operational tooling to build an independent, monetized leak ecosystem. The report documents a breach model that mixes everyday developer risk (secrets in git history) with an escalatory playbook against modern AI services — and a commercial twist where the affiliate monetizes extortion without sharing proceeds through the host RaaS.

Read the original report at Infosecurity Magazine: https://www.infosecurity-magazine.com/news/affiliate-doublecrosses-raas/