Cyber Security News

Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks

A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks.

The operator, known as Azazel, combined stolen development credentials, remote command execution and data theft while working with the Gentlemen ransomware group.

The campaign affected more than two dozen organisations across six countries, including logistics, insurance, pharmaceuticals, medical devices and AI businesses.

Most intrusions began with secrets stolen from software build pipelines, while a separate attack exploited an AI medical imaging service.

CloudSEK researchers identified the operation after finding an exposed directory and misconfigured storage infrastructure.

CloudSEK said in a report shared with Cyber Security News (CSN) that the investigation uncovered active data theft, dedicated attack scripts and an independent extortion operation. Published on October 5, 2026, the findings show AI moving beyond assistance with malicious code into direct attack execution.

Earlier reporting on AI assisted ransomware intrusions described similar operational use, although CloudSEK’s investigation documents a distinct campaign and attacker infrastructure.

Ransomware Hacker Uses AI Coding Assistant

Azazel registered a reverse shell handler, which enables remote command execution, as a tool inside an AI coding assistant through Model Context Protocol, or MCP. The protocol connects assistants to external tools, allowing the operator to direct activity through that interface.

The clearest evidence came from a ransom note verification script. It used an MCP command execution function and a fixed authentication token to check six internal hosts, confirming that extortion messages had reached eight different locations across the victim environment.

Those locations included login messages, database settings, a management interface and the victim’s code hosting project. This was not simply an assistant suggesting commands: researchers documented the MCP interface carrying instructions used during an actual intrusion into a compromised network.

Additional scripts showed the attacker had developed and tested the approach across multiple tools. Logs also revealed worldwide searches for exposed MCP ports, matching the broader pattern of scans targeting MCP servers as attackers look for reachable AI integration services.

CloudSEK said it had not identified earlier public reporting of this specific MCP command execution method being used as a criminal control channel.

That assessment concerns the documented technique, rather than establishing that all malicious use of MCP began with this operation.

Output on the storage server also appeared consistent with an AI assistant answering questions about backups, disk performance and scanning large datasets. The evidence suggests AI supported management of the criminal infrastructure as well as execution of attacks against victims.

Credential Theft

Most victims were reached through credentials collected from GitLab pipeline variables and repository history. One compromised GitLab instance provided access to two unrelated organisations, illustrating how shared development infrastructure can spread the consequences of a single exposed access token.

At a software service provider, the breach reached more than 150 databases, payment gateways and hundreds of repositories, affecting over a dozen client companies.

The danger mirrors other cases of stolen build pipeline secrets where exposed credentials create routes into connected business systems.

Another victim lost more than 120,000 financial registry records before the attacker stopped its live database and deleted production data.

Azazel published stolen information through his own leak operation and retained extortion proceeds instead of sharing them with the Gentlemen operator.

Warning message (Source – CloudSEK)

The separate AI platform intrusion began with an imaging API that fetched supplied web addresses without validation. The attacker reached internal services, decrypted stored credentials and recovered an authentication bypass token from repository history.

More than 6TB was stolen, with transfers continuing during the investigation. CloudSEK recommends keeping pipeline secrets in dedicated credential storage, rotating exposed tokens and auditing repository history.

Organisations should restrict MCP services to local access, log privileged tool execution, separate encryption keys from configuration files, limit storage permissions and test backups kept apart from production infrastructure.

Defenders should also watch for unusual pipeline variable reads, unexpected service account token activity and bulk storage transfers. Restrict database command execution and validate uploaded content rather than relying only on a file’s extension.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IPv423.236.169[.]183Command-and-control server and exposed directory; directory listing used port 8000 and uploads used port 9999.
IPv4162.220.163[.]26Active operations staging server and stolen-data repository.
Domainforgitlab[.]comAttacker-owned hostname masquerading as GitLab infrastructure.
IPv466.179.30[.]155Publication and archive server hosting the LEAKNED operation.
IPv4141.95.252[.]30Beacon check-in address.
IPv4:Port66.203.124[.]135:443MEGA cloud transfer destination observed in the campaign; not exclusively malicious infrastructure.
Local endpoint127.0.0.1:35367Loopback MCP endpoint used for attack execution; not a remote attacker address.
MCP client identityhermesClient identity identified by CloudSEK as malicious in this operation.
Scanner fingerprintinternet-census-mcp-scannerFingerprint associated with worldwide scanning for exposed MCP services.
Script filenameva.pyVerified ransom note delivery across six internal hosts through MCP calls.
Script filenamemcp_test.pyMCP testing tooling recovered from the operation.
Script filenamerecon_mcp.pyMCP reconnaissance tooling recovered from the operation.
Script filenamebrute_odoo.pyCustom script for brute-forcing Odoo ERP access.
Script filenamejasypt_decrypt_all.pyDecrypted protected configuration credentials.
Script filenamefind_full_token.shRecovered authentication token material from repository history.
Script filenamegrafana_all.pyMonitoring credential extraction tooling.
Script filenamegrafana_crack3.pyGrafana credential cracking tooling.
Script filenamescan_vectors.pyReconnaissance and infrastructure scanning tooling.
Script filenamesqli_hunt.pyReconnaissance and vulnerability scanning tooling.
Script filenamedeser_hunt.pyReconnaissance and vulnerability scanning tooling.
Script filenamecheck_rce_surface.shScript for checking remote code execution attack surfaces.
Script filenamegbasic_mirror_retry.shSupported incremental object-storage copying with retry handling.
Script filenameargocd_hunt.shTooling listed in connection with lateral movement.
Script filenameloki_analyze.pyAnalysed application logs.
Script filenamemonitoring_grep.shSearched monitoring data.
Ransom note path/root/ATTENTION_SENSITIVE_INFORMATION.txtRansom note placed in the root user’s home directory.
Ransom note path/home/ubuntu/ATTENTION_SENSITIVE_INFORMATION.txtRansom note placed in the Ubuntu user’s home directory.
Modified system file/etc/motdLegitimate system message file used to display an extortion message.
Configuration filenamesshd_configLegitimate SSH configuration file used to configure an extortion banner.
Template filenamelogin_user.htmlLegitimate pgAdmin login template targeted for ransom message placement.
Repository filenameREADMEVictim repository content modified to display an extortion message.
Configuration filenamevalues.yamlLegitimate configuration filename cited as potentially containing embedded secrets; not independently malicious.
Configuration referencedocker-composeConfiguration reference cited as potentially containing embedded secrets; no exact filename extension was supplied.
Credential file referencekubeconfigKubernetes access configuration targeted during credential searches; not independently malicious.
Staging directory/dataDirectory used to stage stolen data on the operations server.
Executable path suffix/mcMinIO Client executable suffix used in the report’s detection rule; legitimate backup activity can also match.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

OpenAI Agents Caught Editing Wikis, Making Millions of Requests That Led to Outage

The Wikimedia Foundation has uncovered unauthorized wiki edits, failed hacking attempts, and millions of automated…

44 minutes ago

Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure

Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services.…

45 minutes ago

Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Dell has released security updates for five vulnerabilities in Dell System Update (DSU), including a…

1 hour ago

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…

3 hours ago

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

4 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

5 hours ago