Ransomware operator ran attacks through an AI coding assistant's MCP tools, CloudSEK finds
CloudSEK documents how ransomware operator Azazel registered a reverse shell handler as an MCP tool inside an AI coding assistant and used it to run attacks across enterprise networks.
A ransomware affiliate has been running intrusions through an AI coding assistant, registering a reverse shell handler as a tool inside the assistant through the Model Context Protocol and directing activity through that interface. The findings come from a CloudSEK report published October 5 and shared with Cyber Security News, documenting a campaign by an operator known as Azazel who worked with the Gentlemen ransomware group and hit more than two dozen organizations across six countries, spanning logistics, insurance, pharmaceuticals, medical devices, and AI companies.
The MCP angle
This is the part that should get developers' attention. Azazel did not just ask an AI for help writing malware. The operator registered a reverse shell handler as a tool in an AI coding assistant via MCP, the protocol that connects assistants to external tools, and used the assistant's interface to carry instructions during an actual intrusion into a compromised network. The clearest evidence came from a ransom-note verification script: it used an MCP command-execution function with a fixed authentication token to check six internal hosts, confirming that extortion messages had reached eight locations across the victim environment, including login messages, database settings, a management interface, and the victim's code hosting project.
CloudSEK also found scripts showing the attacker had developed and tested the approach across multiple tools, plus logs revealing worldwide searches for exposed MCP ports, matching a broader pattern of scans targeting reachable MCP services. The firm says it had not seen earlier public reporting of MCP command execution being used as a criminal control channel. The full report coverage includes CloudSEK's indicators of compromise and defender recommendations.
How the intrusions started
Keep the MCP detail in proportion: most intrusions began with far more conventional failures. CloudSEK found that initial access generally came from secrets stolen out of software build pipelines, including GitLab pipeline variables and repository history. One compromised GitLab instance provided access to two unrelated organizations, showing how shared development infrastructure spreads the blast radius of a single exposed token. At one software service provider, the breach reached more than 150 databases, payment gateways, and hundreds of repositories, affecting over a dozen client companies. Another victim lost more than 120,000 financial registry records before the attacker stopped its live database and deleted production data.
A separate attack exploited an AI medical imaging service whose API fetched supplied web addresses without validation, letting the attacker reach internal services, decrypt stored credentials, and recover an authentication bypass token from repository history. More than 6TB was stolen, with transfers continuing while CloudSEK investigated. And Azazel apparently ran an independent streak: the operator published stolen data through his own leak operation and kept the extortion proceeds instead of sharing them with the Gentlemen operator.
What defenders should take from this
Two lessons, both practical. First, treat MCP servers like any other remote execution surface: restrict them to local access, log privileged tool execution, and do not leave them reachable on the network. The global scans CloudSEK observed suggest attackers are already hunting for exposed ones. Second, the pipeline is the perimeter. Keep secrets in dedicated credential storage, rotate exposed tokens, and audit repository history, because that is still how most of these intrusions begin. All of the above is CloudSEK's reporting; the technique is documented from the operator's own recovered infrastructure, which is about as close to ground truth as these reports get.