A Russian-speaking Gentlemen ransomware affiliate used the Model Context Protocol (MCP) to execute commands during live intrusions, turning an AI coding assistant’s tool interface into an operational command-and-control channel. CloudSEK identified the activity while investigating exposed infrastructure belonging to an operator calling himself Azazel. Azazel also operated LEAKNED, an independent leak site that allegedly diverted […] The post Gentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/ransomware-affiliate-operations/
![]()

