Skip to content
Ransomware Affiliate Azazel Betrays Gang, Exfiltrates Data from Multiple Victims

Ransomware Affiliate Azazel Betrays Gang, Exfiltrates Data from Multiple Victims

First seen 6 Oct 2026, 14:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 15:57 UTC
  • •Azazel, a ransomware affiliate, betrayed The Gentlemen RaaS by creating his own leak site.
  • •He exploited GitLab CI/CD secrets and SSRF vulnerabilities to exfiltrate over 6TB of data.
  • •CloudSEK's report indicates Azazel's operations reflect advanced cybercriminal tactics, including AI tooling.

A Russian-speaking ransomware affiliate named Azazel has betrayed his Ransomware as a Service (RaaS) operator, The Gentlemen, by establishing his own leak site called Leakned. Using the group's tools, he extorted over two dozen organizations across six countries, targeting sectors such as logistics, medical services, and government. Azazel's attack methods included exploiting exposed GitLab CI/CD secrets and a server-side request forgery (SSRF) vulnerability in an AI medical-imaging API. He managed to exfiltrate more than 6TB of data and published victim data on his independent site, collecting extortion proceeds without routing them through The Gentlemen. His operations included sophisticated techniques like using AI tools to manage his infrastructure and running attacks through a reverse shell. CloudSEK, which reported these findings, believes Azazel is linked to Russia due to the language used in his operational scripts. The report highlights a significant breach of trust within the cybercriminal community, as this incident follows another recent betrayal involving the ShinyHunters group.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CloudSEK report published
CloudSEK released a report detailing Azazel's betrayal and extensive cybercriminal activities, including data exfiltration from multiple sectors.
Infosecurity-Magazine
2026-10-06
Betrayal news reported
Itpro reported on Azazel's betrayal of The Gentlemen RaaS and his independent operations, highlighting the scale and sophistication of his attacks.
Itpro

More articles in this cluster (2)

Following this threat?

Track BlackLock, ShinyHunters and Mamona in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who are the victims of Azazel's attacks?
Victims include organizations in logistics, medical services, insurance, pharmaceuticals, and government sectors across six countries.
What methods did Azazel use for his attacks?
Azazel exploited exposed GitLab CI/CD secrets and SSRF vulnerabilities in an AI medical-imaging API to gain access to sensitive data.
Is Azazel still active?
Yes, the investigation revealed that data exfiltration was still ongoing at the time of reporting.