A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks.
The operator, known as Azazel, combined stolen development credentials, remote command execution and data theft while working with the Gentlemen ransomware group.
The campaign affected more than two dozen organisations across six countries, including logistics, insurance, pharmaceuticals, medical devices and AI businesses.
Most intrusions began with secrets stolen from software build pipelines, while a separate attack exploited an AI medical imaging service.
CloudSEK researchers identified the operation after finding an exposed directory and misconfigured storage infrastructure.
CloudSEK said in a report shared with Cyber Security News (CSN) that the investigation uncovered active data theft, dedicated attack scripts and an independent extortion operation. Published on October 5, 2026, the findings show AI moving beyond assistance with malicious code into direct attack execution.
Earlier reporting on AI assisted ransomware intrusions described similar operational use, although CloudSEK’s investigation documents a distinct campaign and attacker infrastructure.
Ransomware Hacker Uses AI Coding Assistant
Azazel registered a reverse shell handler, which enables remote command execution, as a tool inside an AI coding assistant through Model Context Protocol, or MCP. The protocol connects assistants to external tools, allowing the operator to direct activity through that interface.
The clearest evidence came from a ransom note verification script. It used an MCP command execution function and a fixed authentication token to check six internal hosts, confirming that extortion messages had reached eight different locations across the victim environment.
Those locations included login messages, database settings, a management interface and the victim’s code hosting project. This was not simply an assistant suggesting commands: researchers documented the MCP interface carrying instructions used during an actual intrusion into a compromised network.
Additional scripts showed the attacker had developed and tested the approach across multiple tools. Logs also revealed worldwide searches for exposed MCP ports, matching the broader pattern of scans targeting MCP servers as attackers look for reachable AI integration services.
CloudSEK said it had not identified earlier public reporting of this specific MCP command execution method being used as a criminal control channel.
That assessment concerns the documented technique, rather than establishing that all malicious use of MCP began with this operation.
Output on the storage server also appeared consistent with an AI assistant answering questions about backups, disk performance and scanning large datasets. The evidence suggests AI supported management of the criminal infrastructure as well as execution of attacks against victims.
Credential Theft
Most victims were reached through credentials collected from GitLab pipeline variables and repository history. One compromised GitLab instance provided access to two unrelated organisations, illustrating how shared development infrastructure can spread the consequences of a single exposed access token.
At a software service provider, the breach reached more than 150 databases, payment gateways and hundreds of repositories, affecting over a dozen client companies.
The danger mirrors other cases of stolen build pipeline secrets where exposed credentials create routes into connected business systems.
Another victim lost more than 120,000 financial registry records before the attacker stopped its live database and deleted production data.
Azazel published stolen information through his own leak operation and retained extortion proceeds instead of sharing them with the Gentlemen operator.
.webp)
The separate AI platform intrusion began with an imaging API that fetched supplied web addresses without validation. The attacker reached internal services, decrypted stored credentials and recovered an authentication bypass token from repository history.
More than 6TB was stolen, with transfers continuing during the investigation. CloudSEK recommends keeping pipeline secrets in dedicated credential storage, rotating exposed tokens and auditing repository history.
Organisations should restrict MCP services to local access, log privileged tool execution, separate encryption keys from configuration files, limit storage permissions and test backups kept apart from production infrastructure.
Defenders should also watch for unusual pipeline variable reads, unexpected service account token activity and bulk storage transfers. Restrict database command execution and validate uploaded content rather than relying only on a file’s extension.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
