Itpro Ransomware Affiliate Azazel Betrays Gang, Exfiltrates Data from Multiple Victims
Article Content
- •Azazel, a ransomware affiliate, betrayed The Gentlemen RaaS by creating his own leak site.
- •He exploited GitLab CI/CD secrets and SSRF vulnerabilities to exfiltrate over 6TB of data.
- •CloudSEK's report indicates Azazel's operations reflect advanced cybercriminal tactics, including AI tooling.
A Russian-speaking ransomware affiliate named Azazel has betrayed his Ransomware as a Service (RaaS) operator, The Gentlemen, by establishing his own leak site called Leakned. Using the group's tools, he extorted over two dozen organizations across six countries, targeting sectors such as logistics, medical services, and government. Azazel's attack methods included exploiting exposed GitLab CI/CD secrets and a server-side request forgery (SSRF) vulnerability in an AI medical-imaging API. He managed to exfiltrate more than 6TB of data and published victim data on his independent site, collecting extortion proceeds without routing them through The Gentlemen. His operations included sophisticated techniques like using AI tools to manage his infrastructure and running attacks through a reverse shell. CloudSEK, which reported these findings, believes Azazel is linked to Russia due to the language used in his operational scripts. The report highlights a significant breach of trust within the cybercriminal community, as this incident follows another recent betrayal involving the ShinyHunters group.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track BlackLock, ShinyHunters and Mamona in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who are the victims of Azazel's attacks?
What methods did Azazel use for his attacks?
Is Azazel still active?
Continue Reading
ShinyHunters Hack Exposes Sensitive FBI Employee Data On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security…
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…