Beelzebub is a named threat actor associated with exploitation of web application flaws in Next.js and related server-side JavaScript ecosystems to enable systematic credential theft and sensitive-data extraction. Activity attributed to this actor includes abuse of vulnerabilities such as CVE-2025-29927 and CVE-2025-66478 to gain code execution and harvest secrets from compromised environments. Observed objectives include extraction of credentials and other sensitive data from affected systems. Based on the available information, Beelzebub is best characterized as an intrusion actor focused on initial access through vulnerability exploitation followed by credential theft and data exfiltration. No high-confidence attribution to a specific country, industry focus, or ransomware/extortion operation is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.