Also known as: Belesn Group, Emperor Dragonfly, tracked as, ThreeAM, Abyss Locker, BlackCat, Noberus, ARCrypter, subsequently expanding globally, Cinnamon Tempest, SLIME34, Babuk2 by other trackers, rapidly targeting both Windows, Linux systems across Asia, Europe, the U.S, technology, electronics, event, DCryptSoft, especially universities in Japan, Hong Kong, black shrantac, DEV-0401, NightSky, Pandora, Fantomas, xoriste, Butler Spider, Cring, firmware, Pay, Grief, Handala Hack Team, Hatef, APT43, Andariel, Lemon, Agenda, MedusaLocker, MedusaReborn, ChileLocker, Water Pombero, ReadMe, Hamsa, Onix, Onyx, Samurai Panda, PLA Navy, APT4, Wisp Team, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon
Belsen Group operates as an initial‑access brokerage and financially driven cybercrime organization. Its primary tactics involve exploiting authentication bypass vulnerabilities in Fortinet FortiGate firewalls (CVE-2022-40684) to gain administrative control, after which it exports detailed firewall configurations and plaintext VPN credentials for a wide array of customers. The leak, released on January 15 2025 via anonymous forums, included IP addresses, passwords, and configuration files from FortiOS 7.0.6 and 7.2.1, presenting a significant risk for unpatched or misconfigured defenses. In addition to the documented exploit, security researchers note that Belsen Group may have also targeted the newer CVE-2024-55591 authentication‑bypass vulnerability affecting FortiOS 8.x series. While concrete evidence of exploitation is not yet publicly confirmed, the pattern suggests a consistent focus on expanding its foothold through unpatched software. The group’s operations are characterized by high-volume data exfiltration and public data dumps, indicating a dual strategy: monetization via ransomware or extortion against individual compromised systems and marketable credential resale via underground forums. The breadth of their target sectors – from healthcare to energy to telecommunications – reflects a opportunistic approach aimed at maximizing potential revenue streams rather than state‑sponsored espionage. Belsen Group’s infrastructure appears decentralized, using publicly accessible management interfaces, possibly with compromised third‑party software or custom backdoors to maintain persistence across network boundaries. The use of obscure aliases and wide geographic distribution further complicates attribution.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Belsen Group is a financially motivated threat actor that has leveraged zero‑day vulnerabilities in Fortinet FortiGate firewalls – notably CVE-2022-40684 and potentially the newer CVE-2024-55591 – to compromise over 15,000 devices worldwide. The group exfiltrated confidential configuration files, VPN credentials, and system details, publishing a large data dump on dark‑web forums that exposed thousands of organizations across Asia, Europe, and North America.
Goals & Targeting
The actor’s strategic objectives center on financial gain through credential theft, data exfiltration, and subsequent exploitation of a diverse portfolio of sectors that include highly data‑rich domains such as healthcare, finance, manufacturing, and critical infrastructure. By targeting globally distributed organizations – especially those with Fortinet firewalls exposed to the Internet – Belsen Group maximizes its attack surface while minimizing defensive barriers. Typical victims are midsize to large enterprises that rely on FortiGate devices for VPN access, often with outdated firmware or insufficient segmentation, allowing the group to harvest administrative accounts and sensitive configuration data for resale or leverage in ransomware campaigns.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first publicly reported activity in early 2025, Belsen Group has demonstrated a rapid escalation in scale, compromising tens of thousands of Fortinet firewalls across multiple continents. Their campaign timeline displays an operational tempo that leverages newly disclosed vulnerabilities promptly, with data exfiltration followed by public dumps within days. Victim profiles tend to be organizations employing older or unpatched FortiOS versions; the group does not limit itself to a single sector but instead attacks any institution offering rich credential sets. Historically, this pattern mirrors typical cybercrime broker models that generate revenue through both direct ransom offers and secondary market reselling of stolen data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core attribution of Belsen Group’s use of CVE-2022-40684 to compromise FortinGate firewalls is well‑documented in multiple independent reports and security advisories. However, evidence regarding the exploitation of CVE-2024-55591 remains tentative; no confirmed activity has yet been linked conclusively to the group. Tool usage claims are largely speculative, inferred from correlated industrial intelligence but lacking direct attribution. Overall confidence in the exploitation narrative is moderate‑high with acknowledged gaps on post‑exploitation tactics and full toolchain validation.
No campaigns linked yet.
No observed data linked yet.
47
Techniques
45
Tools
0
Campaigns
56
IOCs
0
Observed Data
14
Tactics