Gentlemen Ransomware Campaign Abuses MCP for Command Execution
Gentlemen ransomware affiliate Azazel abused Model Context Protocol
(MCP) tooling as a command and control channel during live intrusions. The
campaign targeted GitLab secrets, credentials and cloud infrastructure, using
MCP-based command execution, credential harvesting, data exfiltration and
destructive actions across compromised environments.
Pulse ID: 6ac56b9663bd025854777de2
Pulse Link: https://otx.alienvault.com/pulse/6ac56b9663bd025854777de2
Pulse Author: cryptocti
Created: 2026-10-06 21:43:50
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Gentlemen #RansomWare #Cloud #CredentialHarvesting #OTX #cryptocti