Belsen Group is a threat actor known for exploiting CVE-2022-40684 to compromise over 15,000 FortiGate firewalls.
Analyst brief
Belsen Group is a threat actor that exploited CVE-2022-40684 to compromise over 15,000 FortiGate firewalls, primarily targeting devices running the final vulnerable FortiOS versions 7.0.6 and 7.2.1. Their main TTPs include unauthorized access via this CVE and subsequent leaking of detailed configurations and plaintext VPN credentials, organized by country and IP address. Defenders must prioritize patching critical Fortinet vulnerabilities and strengthen monitoring, as similar exploitation of older CVEs (and potentially CVE-2024-55591) by such threat actors could lead to further credential exposure.
Belsen Group
unknown
The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configurations and plaintext VPN credentials. Their leaked data, organized by country and IP address, primarily consists of configurations from FortiOS 7.0.6 and 7.2.1, which were the last vulnerable versions before patches were issued. Security researcher Kevin Beaumont confirmed that the group leveraged this vulnerability to gain unauthorized access and warned of potential exploitation of CVE-2024-55591 by similar threat actors. Fortinet has stated that the leaked data originates from older campaigns and not from any recent incidents.