Russian Ransomware Affiliate Exploits GitLab Vulnerabilities in Multi-Country Cyberattacks
A Russian-speaking threat actor, operating under the alias Azazel, has been identified as an affiliate of the Gentlemen ransomware group while simultaneously running an independent extortion operation via the LEAKNED data leak site. Researchers from CloudSEK uncovered a series of breaches affecting over two dozen organizations across six countries, spanning sectors including logistics, insurance, pharmaceuticals, AI, medical devices, and government-linked services.
The attacks primarily exploited exposed credentials in GitLab pipelines, configuration files, and repository histories. Using tools like glato, nord-stream, gitlab-secrets, and gitleaks, Azazel harvested sensitive data, including database passwords, API keys, access tokens, and SSH private keys. These credentials enabled lateral movement from development environments into production systems, with one compromised GitLab instance exposing multiple unrelated organizations.
In one case, a single pipeline token granted access to database credentials, shipping service logins, and private keys for three cloud servers. Another breach spread from a software platform to over a dozen customer environments, compromising 150+ databases, payment gateways, and hundreds of source code repositories. A government-linked financial registry lost over 120,000 records, with Azazel deploying a Python script to delete PostgreSQL production data after exfiltration.
The attacker also embedded ransom messages across SSH banners, database settings, GitLab projects, and admin login pages. In a separate attack on an AI platform, an unvalidated imaging API allowed server-side request forgery (SSRF), enabling access to internal services. Azazel decrypted protected configurations using a recovered Jasypt master key, extracted Grafana admin hashes, and exfiltrated over six terabytes of data including Kubernetes configs, SSH keys, and credentials via continuous object storage transfers.
Further investigation revealed the use of Model Context Protocol (MCP) for internal command execution, with scripts automating ransom message delivery across six hosts. The attacker’s infrastructure, split across three servers, boasted over 50 terabytes of storage, with MEGA serving as a final transfer destination. Evidence also suggested the use of an AI assistant for attack planning.
CloudSEK’s findings highlight a sophisticated campaign combining credential theft, data destruction, and AI-assisted operations, though no direct targeting of U.S. military infrastructure was confirmed. The exposed infrastructure provided rare insight into an active ransomware affiliate’s workflow.
Source: https://cyberpress.org/gentlemen-exploits-gitlab-secrets-2/
GitLab TPRM report: https://www.rankiteo.com/company/gitlab-com
"id": "git1791282399",
"linkid": "gitlab-com",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Over 120,000 records '
'(government-linked financial '
'registry), 150+ databases, '
'hundreds of source code '
'repositories',
'industry': ['logistics',
'insurance',
'pharmaceuticals',
'technology',
'healthcare',
'government'],
'location': ['six countries (unspecified)'],
'type': ['logistics',
'insurance',
'pharmaceuticals',
'AI',
'medical devices',
'government-linked services']}],
'attack_vector': ['exposed credentials in GitLab pipelines',
'configuration files',
'repository histories',
'unvalidated imaging API (SSRF)'],
'data_breach': {'data_encryption': 'Yes (ransomware encryption, Jasypt master '
'key decryption)',
'data_exfiltration': 'Yes (over six terabytes, including via '
'MEGA)',
'file_types_exposed': ['configuration files',
'source code',
'database dumps',
'SSH keys',
'Kubernetes configs'],
'number_of_records_exposed': '120,000+ (government-linked '
'financial registry), 150+ '
'databases, hundreds of source '
'code repositories',
'personally_identifiable_information': 'Yes (120,000+ '
'records)',
'sensitivity_of_data': 'High (PII, financial data, '
'credentials, proprietary code)',
'type_of_data_compromised': ['database credentials',
'API keys',
'access tokens',
'SSH private keys',
'Kubernetes configs',
'source code repositories',
'Grafana admin hashes',
'payment gateway logins',
'PII (120,000+ records)']},
'description': 'A Russian-speaking threat actor, operating under the alias '
'*Azazel*, has been identified as an affiliate of the '
'*Gentlemen* ransomware group while simultaneously running an '
'independent extortion operation via the *LEAKNED* data leak '
'site. The attacks exploited exposed credentials in GitLab '
'pipelines, configuration files, and repository histories, '
'leading to breaches across over two dozen organizations in '
'six countries. The attacker used tools like *glato*, '
'*nord-stream*, *gitlab-secrets*, and *gitleaks* to harvest '
'sensitive data, including database passwords, API keys, '
'access tokens, and SSH private keys. This enabled lateral '
'movement from development environments into production '
'systems, with significant data exfiltration and destruction '
'observed.',
'impact': {'brand_reputation_impact': 'Likely significant due to data '
'breaches and extortion',
'data_compromised': 'Over six terabytes of data exfiltrated, '
'including database credentials, API keys, SSH '
'keys, Kubernetes configs, and source code '
'repositories',
'identity_theft_risk': 'High (PII and credentials exposed)',
'operational_impact': 'Data destruction (e.g., PostgreSQL '
'production data deleted), lateral movement '
'into production systems, ransom messages '
'embedded in SSH banners and admin login '
'pages',
'payment_information_risk': 'High (payment gateways compromised)',
'systems_affected': ['GitLab instances',
'production databases',
'cloud servers',
'payment gateways',
'internal services']},
'initial_access_broker': {'backdoors_established': 'Yes (SSH banners, '
'database settings, GitLab '
'projects, admin login '
'pages)',
'entry_point': ['exposed GitLab credentials',
'unvalidated API (SSRF)'],
'high_value_targets': ['production databases',
'payment gateways',
'cloud servers',
'government-linked financial '
'registries']},
'investigation_status': 'Ongoing (researchers uncovered the campaign)',
'lessons_learned': 'Exposed credentials in GitLab pipelines and repositories '
'can lead to widespread lateral movement and data '
'breaches. Unvalidated APIs (e.g., SSRF) pose significant '
'risks. AI-assisted attack planning and automation tools '
'are increasingly used by threat actors. Network '
'segmentation and credential hygiene are critical.',
'motivation': ['financial gain', 'data extortion', 'disruption'],
'post_incident_analysis': {'corrective_actions': ['Remove exposed credentials '
'from GitLab and '
'repositories',
'Validate and secure APIs '
'to prevent SSRF',
'Implement network '
'segmentation',
'Rotate all exposed '
'credentials and keys',
'Deploy monitoring for '
'unusual data transfers'],
'root_causes': ['Exposed credentials in GitLab '
'pipelines and repositories',
'Unvalidated API inputs (SSRF '
'vulnerability)',
'Lack of network segmentation',
'Poor credential hygiene (e.g., '
'hardcoded keys, unrotated '
'tokens)']},
'ransomware': {'data_encryption': 'Yes (production data, ransom messages '
'embedded in systems)',
'data_exfiltration': 'Yes (over six terabytes)',
'ransomware_strain': '*Gentlemen* (affiliate operation)'},
'recommendations': ['Audit GitLab pipelines and repositories for exposed '
'credentials using tools like *gitleaks* and '
'*gitlab-secrets*.',
'Implement strict API validation to prevent SSRF attacks.',
'Enforce network segmentation to limit lateral movement.',
'Monitor for unusual data transfers (e.g., to MEGA or '
'other cloud storage).',
'Rotate credentials and keys regularly, especially in '
'development environments.',
'Deploy enhanced monitoring for GitLab and production '
'systems.',
'Educate developers on secure coding practices and '
'credential management.'],
'references': [{'source': 'CloudSEK'}],
'response': {'third_party_assistance': 'CloudSEK (researchers)'},
'threat_actor': 'Azazel (Russian-speaking, affiliated with *Gentlemen* '
'ransomware group, operates *LEAKNED* data leak site)',
'title': 'Russian Ransomware Affiliate Exploits GitLab Vulnerabilities in '
'Multi-Country Cyberattacks',
'type': ['ransomware', 'data breach', 'extortion'],
'vulnerability_exploited': ['CVE-2021-22205 (GitLab)',
'misconfigured GitLab pipelines',
'unvalidated API inputs']}