Ransomware Affiliate Betrays RaaS Operator, Steals Victim Funds
A ransomware affiliate known as 'Azazel' has been discovered operating independently from his RaaS group, 'The Gentlemen,' secretly extorting victims and stealing funds.

A ransomware affiliate operating under the guise of 'The Gentlemen' RaaS (Ransomware-as-a-Service) group has been found to be running a parallel operation, betraying both his RaaS partners and his victims. Identified as 'Azazel,' this cybercriminal has been secretly extorting at least two dozen global victims, diverting the ransom payments directly to himself rather than sharing them with the RaaS operator.
CloudSEK's report, titled 'The Gentlemen Files,' detailed the sophisticated double-dealing. Researchers uncovered two exposed servers managed by Azazel, which contained terabytes of data stolen from victims across various sectors including logistics, insurance, pharmaceuticals, AI, medical devices, and government entities in six different countries. This independent operation, branded as 'Leakned,' allowed Azazel to publish victim data and collect extortion proceeds without involving The Gentlemen program, a clear breach of the RaaS agreement.
Azazel employed distinct and advanced attack chains. One method involved harvesting sensitive secrets from exposed GitLab infrastructure. This included CI/CD tokens, database credentials, API keys, and SSH private keys, which provided him with access to cloud systems and databases. It is believed these secrets were often found in earlier commits of repositories, even if removed from current versions.
In another notable attack, Azazel targeted a medical-imaging company by exploiting a Server-Side Request Forgery (SSRF) vulnerability within an unauthenticated AI medical-imaging API. This exploit allowed him to map internal services and subsequently locate credentials for internal data stores. This multi-stage compromise, which lasted for weeks, ultimately led to the exfiltration of 6TB of data.
Adding a layer of sophistication, Azazel utilized an AI coding assistant to execute commands on a compromised victim machine via a reverse-shell handler. This integration of AI tooling for operational tasks, alongside global scanning infrastructure for exposed AI assistant ports, demonstrates a skill level significantly beyond that of typical ransomware affiliates.
Furthermore, Azazel's infrastructure choices were unusual. Instead of relying on temporary cloud storage or rented Virtual Private Servers (VPS) common among other Gentlemen affiliates, he maintained a dedicated 29TB staging server and a separate 22TB long-term vault. This setup suggests a more permanent and robust operational infrastructure.
The discovery of Azazel's independent operation highlights the evolving and often treacherous dynamics within the RaaS ecosystem. Affiliates are increasingly demonstrating the capability and willingness to betray their RaaS providers, seeking to maximize their profits by cutting out the middleman and operating entirely on their own terms, even if it means double-crossing their own victims.
This incident underscores the challenges in attributing attacks and managing the affiliate model within RaaS operations. The ability of an affiliate to independently build and maintain leak sites, manage extensive infrastructure, and employ advanced exploitation techniques, all while ostensibly working under a RaaS umbrella, presents a significant challenge for both law enforcement and cybersecurity firms tracking threat actors.