Ransomware Affiliate Azazel Exploits AI Coding Assistant as Attack Channel
Ransomware affiliate Azazel has weaponized an AI coding assistant, using its Model Context Protocol (MCP) to execute commands and manage infrastructure during attacks on over two dozen organizations globally.

A ransomware affiliate, operating under the alias Azazel, has pioneered a novel attack vector by leveraging an AI coding assistant as a direct channel for executing commands and managing infrastructure within compromised enterprise networks. This sophisticated operation, linked to the Gentlemen ransomware group, involved the theft of development credentials and exploited AI services to facilitate intrusions, data theft, and extortion. Researchers from CloudSEK documented this campaign, which impacted more than two dozen organizations across six countries, spanning sectors such as logistics, insurance, pharmaceuticals, medical devices, and AI businesses.
The campaign's initial entry point for most victims was through the compromise of secrets found within software build pipelines, particularly from platforms like GitLab. In a separate instance, an attack specifically targeted an AI medical imaging service. CloudSEK's investigation uncovered evidence of active data exfiltration, custom attack scripts, and an independent extortion operation, highlighting the evolving landscape of AI-assisted cybercrime. The findings, published on October 5, 2026, indicate a shift from AI merely assisting in malicious code generation to its direct use in executing attacks.
Azazel's innovative technique involved registering a reverse shell handler within an AI coding assistant via its Model Context Protocol (MCP). MCP allows AI assistants to connect to and utilize external tools, enabling the operator to direct malicious activities through the assistant's interface. This was not a theoretical application; researchers observed MCP command execution functions being used in real-world intrusion scenarios. A ransom note verification script, for example, utilized an MCP command execution function with a fixed authentication token to confirm successful delivery of extortion messages to six internal hosts across the victim environment.
Further analysis of logs and scripts revealed that the attacker had extensively tested and refined this MCP-based command execution method across multiple tools. The evidence suggests that AI was not only used for direct attack execution but also for managing the criminal infrastructure itself. Logs indicated worldwide scans for exposed MCP ports, aligning with a broader trend of attackers searching for accessible AI integration services. CloudSEK noted that while malicious use of MCP may not be entirely new, their investigation documented the first instance of this specific command execution technique being employed as a criminal control channel.
The primary method for gaining initial access involved credentials pilfered from GitLab pipeline variables and repository histories. The compromise of a single GitLab instance led to access to two unrelated organizations, demonstrating how shared development infrastructure can amplify the impact of a single credential leak. In one particularly severe case at a software service provider, the breach compromised over 150 databases, payment gateways, and hundreds of repositories, affecting more than a dozen client companies. This mirrors other incidents where exposed build pipeline secrets have provided pathways into connected business systems.
Beyond the pipeline compromises, a distinct attack exploited an AI medical imaging service. The attacker leveraged an imaging API that failed to validate supplied web addresses, allowing access to internal services. From there, they decrypted stored credentials and recovered an authentication bypass token from repository history. This led to the exfiltration of over 6TB of data, with transfers continuing even during the investigation. In another instance, a victim lost more than 120,000 financial registry records before the attacker deleted production data and shut down live databases.
CloudSEK has provided several recommendations for organizations to mitigate such threats. These include securely storing pipeline secrets in dedicated credential management systems, rotating exposed tokens regularly, and auditing repository histories for suspicious activity. They also advise restricting MCP services to local access, logging all privileged tool executions, separating encryption keys from configuration files, limiting storage permissions, and maintaining backups separate from production infrastructure. Defenders should remain vigilant for unusual pipeline variable access, anomalous service account token activity, and large-scale data transfers from storage systems.
Indicators of Compromise (IoCs) provided by CloudSEK include specific IP addresses associated with command-and-control servers and staging environments, attacker-owned domain names, a MEGA cloud transfer destination, and an MCP client identity ('hermes') identified as malicious. Additionally, a scanner fingerprint ('internet-census-mcp-scanner') associated with worldwide scanning for exposed MCP services was observed. Specific script filenames like 'va.py' and 'mcp_test.py' were also identified as part of the attack tooling.