Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Belsen Group

Also known as: Belesn Group, Emperor Dragonfly, tracked as, ThreeAM, Abyss Locker, BlackCat, Noberus, ARCrypter, subsequently expanding globally, Cinnamon Tempest, SLIME34, Babuk2 by other trackers, rapidly targeting both Windows, Linux systems across Asia, Europe, the U.S, technology, electronics, event, DCryptSoft, especially universities in Japan, Hong Kong, black shrantac, DEV-0401, NightSky, Pandora, Fantomas, xoriste, Butler Spider, Cring, firmware, Pay, Grief, Handala Hack Team, Hatef, APT43, Andariel, Lemon, Agenda, MedusaLocker, MedusaReborn, ChileLocker, Water Pombero, ReadMe, Hamsa, Onix, Onyx, Samurai Panda, PLA Navy, APT4, Wisp Team, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon

Description

Belsen Group operates as an initial‑access brokerage and financially driven cybercrime organization. Its primary tactics involve exploiting authentication bypass vulnerabilities in Fortinet FortiGate firewalls (CVE-2022-40684) to gain administrative control, after which it exports detailed firewall configurations and plaintext VPN credentials for a wide array of customers. The leak, released on January 15 2025 via anonymous forums, included IP addresses, passwords, and configuration files from FortiOS 7.0.6 and 7.2.1, presenting a significant risk for unpatched or misconfigured defenses. In addition to the documented exploit, security researchers note that Belsen Group may have also targeted the newer CVE-2024-55591 authentication‑bypass vulnerability affecting FortiOS 8.x series. While concrete evidence of exploitation is not yet publicly confirmed, the pattern suggests a consistent focus on expanding its foothold through unpatched software. The group’s operations are characterized by high-volume data exfiltration and public data dumps, indicating a dual strategy: monetization via ransomware or extortion against individual compromised systems and marketable credential resale via underground forums. The breadth of their target sectors – from healthcare to energy to telecommunications – reflects a opportunistic approach aimed at maximizing potential revenue streams rather than state‑sponsored espionage. Belsen Group’s infrastructure appears decentralized, using publicly accessible management interfaces, possibly with compromised third‑party software or custom backdoors to maintain persistence across network boundaries. The use of obscure aliases and wide geographic distribution further complicates attribution.

Goals & Targeting

Targeted Sectors

Healthcare
Manufacturing
Financial services
Government
Education
Telecommunications
Transportation
Critical infrastructure
Energy
Retail
Information technology
Defense
Non profit
Media
Food agriculture
Construction
Mining
Hospitality
Aviation
Pharmaceutical
Utilities
Entertainment
Aerospace
Legal services

Targeted Countries / Regions

US
CA
CN
BR
IN
DE
KR
JP
TW
FR
AE
GB
RU
ES
AU
TR
IT
RO
MX
IL
EG
SG
KP
VN
IQ
IR
AZ
NL

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Belsen Group is a financially motivated threat actor that has leveraged zero‑day vulnerabilities in Fortinet FortiGate firewalls – notably CVE-2022-40684 and potentially the newer CVE-2024-55591 – to compromise over 15,000 devices worldwide. The group exfiltrated confidential configuration files, VPN credentials, and system details, publishing a large data dump on dark‑web forums that exposed thousands of organizations across Asia, Europe, and North America.

Goals & Targeting

The actor’s strategic objectives center on financial gain through credential theft, data exfiltration, and subsequent exploitation of a diverse portfolio of sectors that include highly data‑rich domains such as healthcare, finance, manufacturing, and critical infrastructure. By targeting globally distributed organizations – especially those with Fortinet firewalls exposed to the Internet – Belsen Group maximizes its attack surface while minimizing defensive barriers. Typical victims are midsize to large enterprises that rely on FortiGate devices for VPN access, often with outdated firmware or insufficient segmentation, allowing the group to harvest administrative accounts and sensitive configuration data for resale or leverage in ransomware campaigns.

Enhanced Description

Key Capabilities

  • Exploiting authentication‑bypass vulnerabilities (e.g., CVE-2022-40684)
  • Large‐scale data exfiltration via compromised firewall configurations
  • Credential theft and reuse
  • Use of public dark‑web forums to monetize leaked data
  • Capability to pivot into other attacks using harvested credentials
  • Potential use of multiple remote execution vectors (SSH, SMB, WMI)
  • Persistence through custom backdoors or stolen admin accounts

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Command and Control
Exfiltration
Defense Evasion
Impact

ATT&CK Techniques

T1190
T1059.003
T1068
T1046
T1043
T1021.001
T1047
T1071
T1086
T1555.003
T1112
T1460
T1560
T1037
T1137
T1548
T1549

Software / Tooling

Cobalt Strike
SystemBC
Avaddon
HELLOKITTY
PowerShell
SSH
SMB
WMI
Custom RAT

Campaigns & Victims

Since its first publicly reported activity in early 2025, Belsen Group has demonstrated a rapid escalation in scale, compromising tens of thousands of Fortinet firewalls across multiple continents. Their campaign timeline displays an operational tempo that leverages newly disclosed vulnerabilities promptly, with data exfiltration followed by public dumps within days. Victim profiles tend to be organizations employing older or unpatched FortiOS versions; the group does not limit itself to a single sector but instead attacks any institution offering rich credential sets. Historically, this pattern mirrors typical cybercrime broker models that generate revenue through both direct ransom offers and secondary market reselling of stolen data.

IOC Patterns

  • Exploitation of zero‑day vulnerabilities in Fortinet FortiGate firewalls
  • Public data dumps of firewall configurations and VPN credentials
  • Unauthorized access to management interfaces over HTTPS/Node.js websocket
  • Use of compromised IPs ranging internationally for command & control

Recommended Actions

  • Permanently patch or upgrade all FortiGate devices to the latest FortiOS release.
  • Restrict management interface exposure: enforce internal‑only access or VPN tunneling.
  • Implement multi‑factor authentication for admin and VPN accounts.
  • Audit firewall configurations regularly and monitor for unauthorized account creation.
  • Block or quarantine known malicious IP ranges and domains associated with Belsen Group.
  • Deploy threat intelligence feeds that flag CVE-2022-40684 and CVE-2024-55591 exploitation indicators.
  • Enable logging and alerts for anomalous credential usage and lateral movement attempts on internal networks.

Suggested Tags

APT
Cybercrime
Financial-Motivated
Fortinet Vulnerability
Data Leak
Credential Theft
Global

Confidence Assessment

The core attribution of Belsen Group’s use of CVE-2022-40684 to compromise FortinGate firewalls is well‑documented in multiple independent reports and security advisories. However, evidence regarding the exploitation of CVE-2024-55591 remains tentative; no confirmed activity has yet been linked conclusively to the group. Tool usage claims are largely speculative, inferred from correlated industrial intelligence but lacking direct attribution. Overall confidence in the exploitation narrative is moderate‑high with acknowledged gaps on post‑exploitation tactics and full toolchain validation.

ATT&CK Techniques

Collection
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.ransomlook.io — Cited by web research for: Emperor Dragonfly
  2. connect.securonix.com — Cited by web research for: T1068
  3. www.rapid7.com — Cited by web research for: BlueSky
  4. www.ampcuscyber.com — Cited by web research for: hudsonrock.com
  5. https://outpost24.com/blog/belsen-group-threat-group/ — Cited by AI analysis.
  6. https://mallory.ai/actors/019ab986-dc4f-769e-96c5-04c466f29b9c — Cited by AI analysis.
  7. https://www.rescana.com/post/fortinet-fortigate-firewall-data-leak-belsen-group-exploits-cve-2022-40684-vuln — Cited by AI analysis.
  8. https://www.securityweek.com/data-from-15000-fortinet-firewalls-leaked-by-hackers/ — Cited by AI analysis.
  9. https://fortgale.com/en/advisory/ — Cited by AI analysis.

Intel Summary

47

Techniques

45

Tools

0

Campaigns

56

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Zero-Day Exploitation
Data Exfiltration
APT
espionage
network-vulnerability
Fortinet
Cybercrime
Financial-Motivated
Fortinet Vulnerability
Data Leak
Credential Theft
Global

Details

MITRE ID
APT4
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Germany (DE)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.