CyberSecurity SEE

Ransomware Affiliate Betrays Operator to Steal Victim Funds

Ransomware Affiliate Betrays Operator to Steal Victim Funds

Betrayal in the Ransomware Underworld: Russian-Speaking Cybercriminal Skims Profits from Victims

In a revelation that shakes the foundations of the cybercriminal ecosystem, a Russian-speaking ransomware affiliate has reportedly double-crossed his partners, capitalizing on funds extorted from an array of over two dozen global victims. The insights into this betrayal come from CloudSEK, a prominent threat intelligence firm, which conducted an in-depth investigation detailed in their report titled The Gentlemen Files, released on October 5.

The research unveiled the actions of “Azazel,” an affiliate of the notorious Gentlemen ransomware-as-a-service (RaaS) network. CloudSEK’s findings are alarming, as they describe the exposure of two servers controlled by Azazel, which were found to harbor several terabytes of sensitive data pilfered from a diverse landscape of sectors including logistics, insurance, pharmaceuticals, artificial intelligence, medical devices, and government organizations across six different countries.

The report emphasizes that “Azazel was not operating according to the standard affiliate playbook.” Unlike typical ransomware affiliates, who usually funnel their extortion receipts through the primary RaaS infrastructure, Azazel diverged from this norm by establishing his own independent leak site named “Leakned.” This site facilitated the public dissemination of victim data and directly allowed him to collect extortion proceeds, effectively undermining the entire operation that his partners worked to maintain. This situation represents a significant betrayal, not only of the RaaS framework but also of the victims whose information was exploited.

Delving further into Azazel’s methods, CloudSEK identified two distinct attack chains employed in his operations. The first chain commenced with the illicit harvesting of sensitive secrets from exposed GitLab infrastructure. These secrets comprised major elements such as continuous integration and continuous deployment (CI/CD) tokens, database credentials, application programming interface (API) keys, and secure shell (SSH) private keys. Through these vulnerabilities, Azazel was granted access to critical cloud systems and databases. The investigators noted that although the secrets may have been purged from the current versions of Git repositories, remnants of them persisted in earlier commits, allowing Azazel to uncover them and utilize them to his advantage.

However, Azazel’s activities didn’t stop at stealing Git credentials. He escalated his attacks to target a medical-imaging company by exploiting a server-side request forgery (SSRF) vulnerability within an unauthenticated AI medical-imaging API. This exploitation enabled him to uncover internal services and locations, ultimately leading him on a lengthy quest for credentials to access internal data storage. The compromise was not instantaneous; it unfolded over several weeks as part of a complex, sustained attack that resulted in the theft of a staggering 6 terabytes of sensitive data.

Adding an unexpected twist to the approach, Azazel incorporated an AI-powered coding assistant in his attack strategy. This innovative tactic allowed him to issue commands to a compromised machine situated within the victim’s network, all while connecting the AI tool to a reverse-shell handler via a management command protocol (MCP). The sophistication and ingenuity of Azazel’s methods have raised alarms among cybersecurity experts, as the report states that his techniques surpassed standard affiliate tradecraft.

Moreover, the Chain B engagement demonstrated an advanced skill set characterized by a series of sophisticated maneuvers: SSRF through an AI inference endpoint, decryption protocols, recovering JSON Web Tokens (JWT) from Git history, cracking the data visualization tool Grafana, incremental data synchronization with MinIO, and harvesting Kubernetes kubeconfig files. The report underscores the significantly elevated skill level that Azazel possesses compared to other affiliates, given the operational intricacies involved in these attacks.

In an unusual operational twist, Azazel’s infrastructure also included a massive 29 terabyte dedicated staging server, which was linked to a separate 22 terabyte long-term storage vault. This operational choice of maintaining substantial dedicated storage diverged from the common practice observed among other Gentlemen affiliates, who typically rely on temporary cloud storage solutions or rented virtual private servers (VPS).

As the cyber landscape continues to evolve, incidents such as this serve as critical reminders of the complexities and dangers in the world of ransomware and cybercrime. The betrayal by Azazel not only highlights the challenges faced by ransomware operators in maintaining loyalty among affiliates but also emphasizes the lengths to which cybercriminals will go to optimize their extortion endeavors. CloudSEK’s report raises significant concerns as it sheds light on the ever-adapting methods employed by cybercriminals, making the landscape increasingly perilous for both businesses and individuals who fall victim to such nefarious activities.

Source link

Exit mobile version