Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds

Written by

A Russian-speaking cybercriminal betrayed his ransomware-as-a-service (RaaS) partners to make off with funds extorted from over two dozen global victims, CloudSEK has revealed.

The threat intelligence specialist detailed the double cross in a new report, The Gentlemen Files, published on October 5.

They researchers found two exposed servers managed by “Azazel” – an affiliate of The Gentlemen RaaS outfit – containing several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device, and government victims across six countries.

“Azazel was not running a standard affiliate playbook,” the report revealed.

“He built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims.”

Read more on double-crossing cybercriminals: ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Azazel ran two very different attack chains, according to the report.

The first involved harvesting secrets from exposed GitLab infrastructure including CI/CD tokens, database credentials, API keys and SSH private keys. These provided access to cloud systems and databases.

It’s likely the secrets were deleted by their developers from the current version of Git repositories but remained in earlier commits, which Azazel found.

A Sophisticated Threat Actor

In another case, the hacker targeted a medical-imaging company by exploiting a server-side request forgery (SSRF) vulnerability in an unauthenticated AI medical-imaging API.

This allowed him to discover internal services, before he went searching for credentials to internal data stores, in a "sustained, multi-stage compromise that ran for weeks" and eventually led to the compromise of 6TB of data.

Interestingly, Azazel used an AI coding assistant in this attack to send commands to a compromised machine on the victim’s network. They did so by connecting the AI tool to a reverse-shell handler via MCP.

"The Chain B engagement – SSRF through an AI inference endpoint, Jasypt decryption, JWT recovery from git history, Grafana cracking, MinIO incremental sync, Kubernetes kubeconfig harvesting – reflects a skill level well above standard affiliate tradecraft,” the report claimed.

“The MCP tooling adds a further dimension: operational use against one victim cluster, global scanning infrastructure for exposed AI assistant ports, and confirmed use of AI tooling for the operator's own infrastructure management.”

Unusually, they also maintained a 29TB dedicated staging server connected to a separate 22TB long-term vault, rather than use temporary cloud storage or rented VPS nodes, which is what most Gentlemen affiliates do.

What’s Hot on Infosecurity Magazine?