Ransomware Affiliate Goes Rogue, Running a Private Extortion Site and Keeping the Proceeds
Threat intelligence firm CloudSEK has detailed how a Russian-speaking cybercriminal known as "Azazel" betrayed the ransomware-as-a-service (RaaS) group he worked with. In a report titled The Gentlemen Files, published on October 5, researchers said they found two exposed servers he managed. They held several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device and government victims across six countries. According to the report, he built his own leak site, called Leakned, and collected extortion payments without routing them through The Gentlemen program.
CloudSEK described two different attack methods. In one, Azazel harvested secrets from exposed GitLab infrastructure, including access tokens, database credentials, API keys and SSH private keys, which gave access to cloud systems and databases. The report suggests developers had deleted these secrets from the current version of their code, but they remained in earlier commits, where he found them.
In the other, he targeted a medical-imaging company through a server-side request forgery flaw in an unauthenticated AI medical-imaging API. This let him discover internal services and then hunt for credentials in a weeks-long, multi-stage compromise that led to 6TB of stolen data. CloudSEK also said he used an AI coding assistant, connected via MCP, to send commands to a compromised machine, and judged his skill well above that of a typical affiliate.