No honor amongst thieves, as hacker betrays his own gang

A Russian-speaking ransomware affiliate not only robbed his victims, but secretly cheated his Ransomware as a Service (RaaS) operator by setting up his own leak site.

Hacker Azazel worked as an affiliate of The Gentlemen ransomware group, according to recent research from CloudSEK. Using its tooling, negotiation channels and ransom note template, he attacked more than two dozen organizations in six countries.

Organizations targeted spanned industries such as logistics, medical services, insurance, pharmaceuticals, and government-adjacent sectors.

CloudSEK said it was far larger than a typical affiliate setup, with more than 50TB of dedicated physical servers, including a 22TB long-term vault built to retain the proceeds across multiple campaigns.

However, researchers noted that Azazel was not running a standard affiliate playbook.

"He built and operated his own independent leak site under the brand LEAKNED, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims," CloudSEK said.

"One exfiltration was still actively running during the investigation, with a target directory growing by hundreds of gigabytes between observations."

Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

All the confirmed victims were reached through stolen CI/CD secrets: a single compromised GitLab instance was used with two organizations, while one CI/CD token exposed more than 150 databases across a SaaS platform and its clients.

A first of its kind campaign?

Notably, in what CloudSEK describes as a criminal first with AI tooling, Azazel registered a reverse shell as a callable tool inside an AI agent harness via the Model Context Protocol (MCP) and ran his attacks through it.

He also built infrastructure to scan the internet for exposed AI assistant ports, and used an AI assistant to manage his own criminal infrastructure.

In one case during an attack on an AI company, a sustained compromise began with an unvalidated AI imaging API, then moved through bulk credential decryption, a JWT token recovered from git history, offline Grafana password cracking and a full Kubernetes sweep.

More than 6TB was taken, and the transfer was still running when investigators found it.

In another, involving a government-linked financial registry, Azazel exfiltrated more than 120,000 records, then deleted the victim's live production database.

Double-crossing hacker has Russian ties

CloudSEK believes that Azazel is Russia-linked, thanks to the fluent Russian language used in operational scripts, while the staging server was codenamed "novostnik" - Russian for "newsman".

The news of Azazel's betrayal comes just weeks after it was revealed that hacking collective ShinyHunters launched an attack on rival cyber crime group Clop after long-running tensions between the two groups.

ShinyHunters hijacked Clop's dark web data leak site, leaving the message: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS... Maybe don't try to threaten us next time", and demanded a ransom.

Similarly, research from Sophos last year revealed Russian-speaking group DragonHub took down the site of rival RansomHub, after which a RansomHub member defaced DragonForce’s site, labeling the group “traitors.”

It also apparently defaced the leak sites operated by the BlackLock and Mamona ransomware groups.

FOLLOW US ON SOCIAL MEDIA

You can also .

Original source No honor amongst thieves, as hacker betrays his own gang

Back to home