Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks.

The operator, known as Azazel, combined stolen development credentials, remote command execution and data theft while working with the Gentlemen ransomware group.

The campaign affected more than two dozen organisations across six countries, including logistics, insurance, pharmaceuticals, medical devices and AI businesses.

Most intrusions began with secrets stolen from software build pipelines, while a separate attack exploited an AI medical imaging service.

CloudSEK researchers identified the operation after finding an exposed directory and misconfigured storage infrastructure.

CloudSEK said in a report shared with Cyber Security News (CSN) that the investigation uncovered active data theft, dedicated attack scripts and an independent extortion operation. Published on October 5, 2026, the findings show AI moving beyond assistance with malicious code into direct attack execution.

Earlier reporting on AI assisted ransomware intrusions described similar operational use, although CloudSEK’s investigation documents a distinct campaign and attacker infrastructure.

Ransomware Hacker Uses AI Coding Assistant

Azazel registered a reverse shell handler, which enables remote command execution, as a tool inside an AI coding assistant through Model Context Protocol, or MCP. The protocol connects assistants to external tools, allowing the operator to direct activity through that interface.

The clearest evidence came from a ransom note verification script. It used an MCP command execution function and a fixed authentication token to check six internal hosts, confirming that extortion messages had reached eight different locations across the victim environment.

Those locations included login messages, database settings, a management interface and the victim’s code hosting project. This was not simply an assistant suggesting commands: researchers documented the MCP interface carrying instructions used during an actual intrusion into a compromised network.

Additional scripts showed the attacker had developed and tested the approach across multiple tools. Logs also revealed worldwide searches for exposed MCP ports, matching the broader pattern of scans targeting MCP servers as attackers look for reachable AI integration services.

CloudSEK said it had not identified earlier public reporting of this specific MCP command execution method being used as a criminal control channel.

That assessment concerns the documented technique, rather than establishing that all malicious use of MCP began with this operation.

Output on the storage server also appeared consistent with an AI assistant answering questions about backups, disk performance and scanning large datasets. The evidence suggests AI supported management of the criminal infrastructure as well as execution of attacks against victims.

Credential Theft

Most victims were reached through credentials collected from GitLab pipeline variables and repository history. One compromised GitLab instance provided access to two unrelated organisations, illustrating how shared development infrastructure can spread the consequences of a single exposed access token.

At a software service provider, the breach reached more than 150 databases, payment gateways and hundreds of repositories, affecting over a dozen client companies.

The danger mirrors other cases of stolen build pipeline secrets where exposed credentials create routes into connected business systems.

Another victim lost more than 120,000 financial registry records before the attacker stopped its live database and deleted production data.

Azazel published stolen information through his own leak operation and retained extortion proceeds instead of sharing them with the Gentlemen operator.

Warning message (Source - CloudSEK)
Warning message (Source – CloudSEK)

The separate AI platform intrusion began with an imaging API that fetched supplied web addresses without validation. The attacker reached internal services, decrypted stored credentials and recovered an authentication bypass token from repository history.

More than 6TB was stolen, with transfers continuing during the investigation. CloudSEK recommends keeping pipeline secrets in dedicated credential storage, rotating exposed tokens and auditing repository history.

Organisations should restrict MCP services to local access, log privileged tool execution, separate encryption keys from configuration files, limit storage permissions and test backups kept apart from production infrastructure.

Defenders should also watch for unusual pipeline variable reads, unexpected service account token activity and bulk storage transfers. Restrict database command execution and validate uploaded content rather than relying only on a file’s extension.

Indicators of compromise (IoCs):-

Type Indicator Description
IPv4 23.236.169[.]183 Command-and-control server and exposed directory; directory listing used port 8000 and uploads used port 9999.
IPv4 162.220.163[.]26 Active operations staging server and stolen-data repository.
Domain forgitlab[.]com Attacker-owned hostname masquerading as GitLab infrastructure.
IPv4 66.179.30[.]155 Publication and archive server hosting the LEAKNED operation.
IPv4 141.95.252[.]30 Beacon check-in address.
IPv4:Port 66.203.124[.]135:443 MEGA cloud transfer destination observed in the campaign; not exclusively malicious infrastructure.
Local endpoint 127.0.0.1:35367 Loopback MCP endpoint used for attack execution; not a remote attacker address.
MCP client identity hermes Client identity identified by CloudSEK as malicious in this operation.
Scanner fingerprint internet-census-mcp-scanner Fingerprint associated with worldwide scanning for exposed MCP services.
Script filename va.py Verified ransom note delivery across six internal hosts through MCP calls.
Script filename mcp_test.py MCP testing tooling recovered from the operation.
Script filename recon_mcp.py MCP reconnaissance tooling recovered from the operation.
Script filename brute_odoo.py Custom script for brute-forcing Odoo ERP access.
Script filename jasypt_decrypt_all.py Decrypted protected configuration credentials.
Script filename find_full_token.sh Recovered authentication token material from repository history.
Script filename grafana_all.py Monitoring credential extraction tooling.
Script filename grafana_crack3.py Grafana credential cracking tooling.
Script filename scan_vectors.py Reconnaissance and infrastructure scanning tooling.
Script filename sqli_hunt.py Reconnaissance and vulnerability scanning tooling.
Script filename deser_hunt.py Reconnaissance and vulnerability scanning tooling.
Script filename check_rce_surface.sh Script for checking remote code execution attack surfaces.
Script filename gbasic_mirror_retry.sh Supported incremental object-storage copying with retry handling.
Script filename argocd_hunt.sh Tooling listed in connection with lateral movement.
Script filename loki_analyze.py Analysed application logs.
Script filename monitoring_grep.sh Searched monitoring data.
Ransom note path /root/ATTENTION_SENSITIVE_INFORMATION.txt Ransom note placed in the root user’s home directory.
Ransom note path /home/ubuntu/ATTENTION_SENSITIVE_INFORMATION.txt Ransom note placed in the Ubuntu user’s home directory.
Modified system file /etc/motd Legitimate system message file used to display an extortion message.
Configuration filename sshd_config Legitimate SSH configuration file used to configure an extortion banner.
Template filename login_user.html Legitimate pgAdmin login template targeted for ransom message placement.
Repository filename README Victim repository content modified to display an extortion message.
Configuration filename values.yaml Legitimate configuration filename cited as potentially containing embedded secrets; not independently malicious.
Configuration reference docker-compose Configuration reference cited as potentially containing embedded secrets; no exact filename extension was supplied.
Credential file reference kubeconfig Kubernetes access configuration targeted during credential searches; not independently malicious.
Staging directory /data Directory used to stage stolen data on the operations server.
Executable path suffix /mc MinIO Client executable suffix used in the report’s detection rule; legitimate backup activity can also match.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks appeared first on Cyber Security News.