Azazel is a Russian-speaking cybercriminal and affiliate of The Gentlemen ransomware-as-a-service operation who also operates LEAKNED, an independent data-leak and extortion service. Azazel has used The Gentlemen's tooling, infrastructure, negotiation channels, and ransom-note templates while separately publishing stolen information through LEAKNED. Identified intrusions affected more than two dozen organizations across six countries, including logistics, insurance, pharmaceuticals, medical devices, artificial intelligence, software services, and government-linked infrastructure. Russian-language operational material establishes a linguistic association but does not establish the operator's country of origin. Azazel primarily obtains initial access by harvesting credentials from GitLab CI/CD variables and repository history, including database passwords, API tokens, and SSH private keys. Compromised shared development infrastructure has enabled access to unrelated organizations and downstream customers. The operator conducts reconnaissance, vulnerability scanning, brute-force attacks, credential decryption, offline password cracking, and lateral movement. In a separate intrusion against an AI medical-imaging platform, server-side request forgery exposed internal services; recovered configuration secrets and an authentication-bypass token enabled further access and the theft of more than 6 TB of data. A distinctive operational technique is the use of Model Context Protocol execution tools connected to an AI coding assistant as a command-and-control interface for executing commands inside compromised networks. Azazel also scans for exposed MCP services and uses MCP-mediated commands to verify ransom messages across internal systems. Exfiltration involves database exports, continuous object-storage mirroring, intermediate staging servers, and cloud-storage transfers. Operations have included extensive database and source-code theft, publication of stolen data, and destructive actions against production databases. One compromise exposed more than 120,000 financial-registry records before the operator stopped the live database and deleted production data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The named operator and associated campaign affiliated with The Gentlemen. Exposed infrastructure revealed more than two dozen victim directories across six unnamed countries. The campaign targeted logistics, insurance, pharmaceuticals, artificial intelligence, medical devices, and government-adjacent infrastructure, using MCP-assisted command execution, credential harvesting, and ongoing data exfiltration.
A named ransomware affiliate conducting intrusions, data theft and extortion against more than two dozen organisations across six unspecified countries. Azazel used an AI coding assistant connected through Model Context Protocol (MCP) as an interface for executing commands inside compromised networks. The operator also maintained an independent leak operation and reportedly retained extortion proceeds rather than sharing them with Gentlemen.
Russian-speaking affiliate of Gentlemen who compromised more than two dozen organizations, stole data, and independently extorted victims through the LEAKNED publication brand, reportedly withholding proceeds from the ransomware operator. Most compromises involved stolen CI/CD secrets; a separate AI-platform intrusion involved sustained credential harvesting and multi-terabyte exfiltration. The investigation also documented MCP-based attack execution and scanning for exposed MCP services. Russian-language artifacts establish language proficiency, not nationality or state sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.