A Russian-speaking Gentlemen ransomware affiliate used the Model Context Protocol (MCP) to execute commands during live intrusions, turning an AI coding assistant’s tool interface into an operational command-and-control channel. CloudSEK identified the activity while investigating exposed infrastructure belonging to an operator calling himself Azazel. Azazel also operated LEAKNED, an independent leak site that allegedly diverted […]
Read the original article:
