When MCP Becomes Part of the Breach

Overview

A ransomware affiliate has demonstrated a new use of AI infrastructure during attacks: turning an AI coding assistant into a channel for executing commands inside compromised enterprise environments. CloudSEK researchers linked the activity to an operator known as Azazel, who worked with the Gentlemen ransomware group while targeting more than two dozen organisations across six countries. The victims included organisations in logistics, insurance, pharmaceuticals, medical devices and artificial intelligence. The significance is not simply that AI was used during a ransomware operation. The more important development is that Model Context Protocol (MCP) was incorporated into the operational attack path, allowing an AI assistant interface to carry commands into compromised systems.

MCP Becomes an Attack Path

MCP is designed to connect AI assistants with external tools and services. In legitimate environments, this can allow an AI assistant to interact with development platforms, databases, files and other resources. In this campaign, researchers found evidence that the attacker registered a reverse-shell handler as an executable tool through MCP. A ransom-note verification script then used an MCP command-execution function and an authentication token to interact with multiple internal hosts. This represents an important distinction. The AI assistant was not simply recommending commands to an attacker. The MCP interface was being used as an operational control channel during an intrusion. The same capability that makes AI assistants useful in development environments can therefore become dangerous when a compromised environment exposes powerful tools through an insufficiently restricted integration.

Stolen Development Secrets Opened the Door

The majority of the documented intrusions reportedly began with credentials stolen from GitLab pipeline variables and repository history. This highlights another critical architectural weakness: software development environments increasingly contain credentials capable of reaching production systems, databases, cloud services and other organisations. In one case, a compromised GitLab instance provided access to two unrelated organisations. At another victim, the compromise reportedly reached more than 150 databases, payment gateways and hundreds of repositories. The AI component therefore did not replace conventional intrusion techniques. Instead, it was layered onto an existing chain involving stolen credentials, privileged access, reconnaissance, command execution and data theft.

The Trust Problem Extends Into AI Tooling

The campaign demonstrates why MCP servers and AI tool integrations should not automatically inherit the trust of the applications they connect to. An AI assistant capable of executing commands effectively becomes another privileged identity within the environment. If that capability can access databases, shells, repositories or infrastructure management systems without sufficiently narrow authorisation, compromising the integration can provide an attacker with an alternative route through the organisation. The risk is amplified when MCP services are remotely reachable or when authentication tokens are broadly shared. A tool intended to improve developer productivity can unintentionally become a new control plane. AI integrations therefore require the same security principles applied to other privileged infrastructure: least privilege, strong authentication, network isolation, detailed logging and explicit authorisation for high-impact actions.

Protect the Pipeline and the Control Plane

The campaign reinforces the importance of keeping development secrets out of source repositories and pipeline variables where practical, rotating exposed credentials and auditing repository history for previously committed secrets. MCP services should be restricted to trusted environments rather than unnecessarily exposed to the internet. Privileged tool execution should be logged, service accounts should have narrowly defined permissions, and database command execution should be tightly controlled. Monitoring should also extend beyond conventional endpoint indicators. Unexpected pipeline-variable access, unusual service-account activity, bulk database queries, large outbound transfers and unexplained MCP tool execution can provide important signals. The objective is not to prevent AI from interacting with enterprise systems. It is to ensure that an AI tool cannot quietly become an unrestricted administrative pathway.

Expert in the Cloud Insight

The most important lesson from this campaign is that AI does not need to be the original entry point to become a significant part of an attack. Once an attacker gains credentials, AI tooling can potentially provide another mechanism for reconnaissance, command execution and interaction with connected enterprise services. MCP makes that possibility particularly important because it creates a standardised bridge between an AI model and external capabilities. Enterprise security architecture therefore needs to treat AI integrations as part of the privileged computing environment. The moment an AI assistant can execute a command, access a database or modify infrastructure, it stops being merely an assistant and becomes another security boundary that must be defended.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.