Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
Key Takeaways A ransomware affiliate, Azazel, leveraged an AI coding assistant to facilitate attacks within enterprise networks. The campaign impacted over 25 organizations across six countries,...
Key Takeaways
- A ransomware affiliate, Azazel, leveraged an AI coding assistant to facilitate attacks within enterprise networks.
- The campaign impacted over 25 organizations across six countries, spanning sectors like logistics, pharmaceuticals, and AI.
- Initial access often involved stolen credentials from software build pipelines, with one specific attack targeting an AI medical imaging service.
- Azazel utilized the AI assistant’s Model Context Protocol (MCP) to execute remote commands, verify ransom note delivery, and manage criminal infrastructure.
- Security researchers at CloudSEK discovered the operation and reported on this novel use of AI for direct attack execution.
Ransomware Hacker Uses AI Coding Assistant for Enterprise Infiltration
A ransomware affiliate, identified as “Azazel,” has been observed weaponizing an AI coding assistant to launch and manage attacks within targeted enterprise networks. This sophisticated operation involved combining stolen development credentials, achieving remote command execution, and exfiltrating sensitive data, all while collaborating with the Gentlemen ransomware group.
Table Of Content
The campaign’s breadth was significant, affecting more than two dozen organizations across six countries. Victims included companies in critical sectors such as logistics, insurance, pharmaceuticals, medical devices, and artificial intelligence. The primary vector for many of these intrusions involved credentials pilfered from software build pipelines. In one notable incident, attackers exploited an AI medical imaging service.
CloudSEK researchers uncovered this activity after identifying an exposed directory and misconfigured storage infrastructure. In a detailed report, CloudSEK said their investigation revealed ongoing data theft, custom attack scripts, and an independent extortion scheme. Published on October 5, 2026, these findings represent a significant shift, demonstrating AI’s evolution from merely assisting with malicious code generation to directly executing attacks. While previous reports detailed AI-assisted ransomware, CloudSEK’s analysis highlights a distinct campaign with unique attacker infrastructure.
Exploiting AI Coding Assistants for Remote Execution
Azazel established a reverse shell handler, a mechanism for remote command execution, by registering it as a tool within an AI coding assistant. This was achieved through the Model Context Protocol (MCP), which enables AI assistants to interface with external tools. This integration allowed Azazel to direct malicious activities through the AI assistant’s interface.
Compelling evidence of this technique emerged from a ransom note verification script. This script leveraged an MCP command execution function, coupled with a fixed authentication token, to confirm the delivery of extortion messages to eight distinct locations within a victim’s environment across six internal hosts. These locations encompassed login interfaces, database configurations, a management console, and the victim’s code hosting project. Critically, researchers confirmed that the MCP interface was not merely suggesting commands but actively transmitting instructions during an actual network intrusion.
Further analysis of recovered scripts indicated that the attacker had thoroughly developed and tested this approach across various tools. Log data also revealed global scans for exposed MCP ports, aligning with a broader trend of attackers seeking vulnerable AI integration services. CloudSEK noted that this specific method of using MCP for criminal command and control had not been publicly reported prior to this operation. This assessment pertains to the documented technique, not to suggest that all malicious uses of MCP originated with this particular campaign.
Evidence from the storage server logs further suggested that the AI assistant was also employed for managing the criminal infrastructure itself. The assistant was observed answering queries related to backups, disk performance, and large dataset scanning. This indicates that AI played a dual role: both in executing attacks against victims and in supporting the management of the attacker’s operational backend.
Credential Theft and Data Exfiltration
The majority of victim compromises stemmed from credentials extracted from GitLab pipeline variables and repository history. In one instance, a single compromised GitLab instance provided access to two distinct and unrelated organizations, underscoring the cascading impact that a single exposed access token within shared development infrastructure can have.
At a software service provider, the breach escalated to encompass over 150 databases, payment gateways, and hundreds of repositories, ultimately affecting more than a dozen client companies. This scenario parallels other incidents involving stolen build pipeline secrets, where exposed credentials create avenues into interconnected business systems.
Another victim suffered the loss of over 120,000 financial registry records. The attacker not only exfiltrated this data but also shut down the live database and deleted production data. Azazel subsequently published the stolen information via his own leak operation, retaining the extortion proceeds rather than sharing them with the Gentlemen ransomware operator.
The separate intrusion into an AI platform began with an imaging API that processed provided web addresses without proper validation. This vulnerability allowed the attacker to access internal services, decrypt stored credentials, and retrieve an authentication bypass token from the repository history. During the investigation, over 6TB of data was observed being exfiltrated, with transfers continuing actively.
What You Should Do
- Store pipeline secrets in dedicated, secure credential management systems.
- Implement a regular rotation schedule for all exposed access tokens.
- Conduct thorough audits of repository history to identify and remove sensitive information.
- Restrict Model Context Protocol (MCP) services to local access only, preventing external exposure.
- Ensure comprehensive logging of all privileged tool execution, especially those involving AI assistants.
- Separate encryption keys from configuration files to prevent their simultaneous compromise.
- Apply the principle of least privilege to all storage permissions.
- Regularly test backups and ensure they are stored independently from production infrastructure.
- Monitor for unusual activity, such as unexpected pipeline variable reads, abnormal service account token usage, and bulk storage transfers.
- Restrict the execution of direct database commands.
- Implement robust content validation for all uploaded files, rather than relying solely on file extensions.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 23.236.169[.]183 |
Command-and-control server and exposed directory; directory listing used port 8000 and uploads used port 9999. Full Report |
| IPv4 | 162.220.163[.]26 |
Active operations staging server and stolen-data repository. |
| Domain | forgitlab[.]com |
Attacker-owned hostname masquerading as GitLab infrastructure. |
| IPv4 | 66.179.30[.]155 |
Publication and archive server hosting the LEAKNED operation. |
| IPv4 | 141.95.252[.]30 |
Beacon check-in address. |
| IPv4:Port | 66.203.124[.]135:443 |
MEGA cloud transfer destination observed in the campaign; not exclusively malicious infrastructure. Full Report |
| Local endpoint | 127.0.0.1:35367 |
Loopback MCP endpoint used for attack execution; not a remote attacker address. |
| MCP client identity | hermes |
Client identity identified by CloudSEK as malicious in this operation. |
| Scanner fingerprint | internet-census-mcp-scanner |
Fingerprint associated with worldwide scanning for exposed MCP services. <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/983d8081-cea9-4009-80a0-eaa374946a56/Ransomware-Hacker-Uses-
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.