Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Home/Threats/Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
Threats

Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks

Key Takeaways A ransomware affiliate, Azazel, leveraged an AI coding assistant to facilitate attacks within enterprise networks. The campaign impacted over 25 organizations across six countries,...

Sarah simpson
Sarah simpson
October 6, 2026 5 Min Read
3 0

Key Takeaways

  • A ransomware affiliate, Azazel, leveraged an AI coding assistant to facilitate attacks within enterprise networks.
  • The campaign impacted over 25 organizations across six countries, spanning sectors like logistics, pharmaceuticals, and AI.
  • Initial access often involved stolen credentials from software build pipelines, with one specific attack targeting an AI medical imaging service.
  • Azazel utilized the AI assistant’s Model Context Protocol (MCP) to execute remote commands, verify ransom note delivery, and manage criminal infrastructure.
  • Security researchers at CloudSEK discovered the operation and reported on this novel use of AI for direct attack execution.

Ransomware Hacker Uses AI Coding Assistant for Enterprise Infiltration

A ransomware affiliate, identified as “Azazel,” has been observed weaponizing an AI coding assistant to launch and manage attacks within targeted enterprise networks. This sophisticated operation involved combining stolen development credentials, achieving remote command execution, and exfiltrating sensitive data, all while collaborating with the Gentlemen ransomware group.

Table Of Content

  • Key Takeaways
  • Ransomware Hacker Uses AI Coding Assistant for Enterprise Infiltration
  • Exploiting AI Coding Assistants for Remote Execution
  • Credential Theft and Data Exfiltration
  • What You Should Do
  • Indicators of Compromise (IoCs)

The campaign’s breadth was significant, affecting more than two dozen organizations across six countries. Victims included companies in critical sectors such as logistics, insurance, pharmaceuticals, medical devices, and artificial intelligence. The primary vector for many of these intrusions involved credentials pilfered from software build pipelines. In one notable incident, attackers exploited an AI medical imaging service.

CloudSEK researchers uncovered this activity after identifying an exposed directory and misconfigured storage infrastructure. In a detailed report, CloudSEK said their investigation revealed ongoing data theft, custom attack scripts, and an independent extortion scheme. Published on October 5, 2026, these findings represent a significant shift, demonstrating AI’s evolution from merely assisting with malicious code generation to directly executing attacks. While previous reports detailed AI-assisted ransomware, CloudSEK’s analysis highlights a distinct campaign with unique attacker infrastructure.

Exploiting AI Coding Assistants for Remote Execution

Azazel established a reverse shell handler, a mechanism for remote command execution, by registering it as a tool within an AI coding assistant. This was achieved through the Model Context Protocol (MCP), which enables AI assistants to interface with external tools. This integration allowed Azazel to direct malicious activities through the AI assistant’s interface.

Compelling evidence of this technique emerged from a ransom note verification script. This script leveraged an MCP command execution function, coupled with a fixed authentication token, to confirm the delivery of extortion messages to eight distinct locations within a victim’s environment across six internal hosts. These locations encompassed login interfaces, database configurations, a management console, and the victim’s code hosting project. Critically, researchers confirmed that the MCP interface was not merely suggesting commands but actively transmitting instructions during an actual network intrusion.

Further analysis of recovered scripts indicated that the attacker had thoroughly developed and tested this approach across various tools. Log data also revealed global scans for exposed MCP ports, aligning with a broader trend of attackers seeking vulnerable AI integration services. CloudSEK noted that this specific method of using MCP for criminal command and control had not been publicly reported prior to this operation. This assessment pertains to the documented technique, not to suggest that all malicious uses of MCP originated with this particular campaign.

Evidence from the storage server logs further suggested that the AI assistant was also employed for managing the criminal infrastructure itself. The assistant was observed answering queries related to backups, disk performance, and large dataset scanning. This indicates that AI played a dual role: both in executing attacks against victims and in supporting the management of the attacker’s operational backend.

Credential Theft and Data Exfiltration

The majority of victim compromises stemmed from credentials extracted from GitLab pipeline variables and repository history. In one instance, a single compromised GitLab instance provided access to two distinct and unrelated organizations, underscoring the cascading impact that a single exposed access token within shared development infrastructure can have.

At a software service provider, the breach escalated to encompass over 150 databases, payment gateways, and hundreds of repositories, ultimately affecting more than a dozen client companies. This scenario parallels other incidents involving stolen build pipeline secrets, where exposed credentials create avenues into interconnected business systems.

Another victim suffered the loss of over 120,000 financial registry records. The attacker not only exfiltrated this data but also shut down the live database and deleted production data. Azazel subsequently published the stolen information via his own leak operation, retaining the extortion proceeds rather than sharing them with the Gentlemen ransomware operator.

The separate intrusion into an AI platform began with an imaging API that processed provided web addresses without proper validation. This vulnerability allowed the attacker to access internal services, decrypt stored credentials, and retrieve an authentication bypass token from the repository history. During the investigation, over 6TB of data was observed being exfiltrated, with transfers continuing actively.

What You Should Do

  • Store pipeline secrets in dedicated, secure credential management systems.
  • Implement a regular rotation schedule for all exposed access tokens.
  • Conduct thorough audits of repository history to identify and remove sensitive information.
  • Restrict Model Context Protocol (MCP) services to local access only, preventing external exposure.
  • Ensure comprehensive logging of all privileged tool execution, especially those involving AI assistants.
  • Separate encryption keys from configuration files to prevent their simultaneous compromise.
  • Apply the principle of least privilege to all storage permissions.
  • Regularly test backups and ensure they are stored independently from production infrastructure.
  • Monitor for unusual activity, such as unexpected pipeline variable reads, abnormal service account token usage, and bulk storage transfers.
  • Restrict the execution of direct database commands.
  • Implement robust content validation for all uploaded files, rather than relying solely on file extensions.

Indicators of Compromise (IoCs)

Type Indicator Description
IPv4 23.236.169[.]183 Command-and-control server and exposed directory; directory listing used port 8000 and uploads used port 9999. Full Report
IPv4 162.220.163[.]26 Active operations staging server and stolen-data repository.
Domain forgitlab[.]com Attacker-owned hostname masquerading as GitLab infrastructure.
IPv4 66.179.30[.]155 Publication and archive server hosting the LEAKNED operation.
IPv4 141.95.252[.]30 Beacon check-in address.
IPv4:Port 66.203.124[.]135:443 MEGA cloud transfer destination observed in the campaign; not exclusively malicious infrastructure. Full Report
Local endpoint 127.0.0.1:35367 Loopback MCP endpoint used for attack execution; not a remote attacker address.
MCP client identity hermes Client identity identified by CloudSEK as malicious in this operation.
Scanner fingerprint internet-census-mcp-scanner Fingerprint associated with worldwide scanning for exposed MCP services. <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/983d8081-cea9-4009-80a0-eaa374946a56/Ransomware-Hacker-Uses-

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution

Next Post

Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us