Funding
Beelzebub Raises €3M to Scale AI-Powered Deception Across Enterprise Networks

Italian cybersecurity startup Beelzebub has raised €3 million in seed funding to expand its AI-powered platform for detecting and trapping attackers inside enterprise networks.
The round was led exclusively by Italian deep-tech venture capital firm United Ventures. Beelzebub plans to use the capital to grow its research team, acquire customers across Europe and open commercial offices in Rome and San Francisco by the end of 2026.
The Milan-based company is targeting organisations that face increasingly automated cyberattacks, particularly operators subject to the European Union’s Network and Information Security Directive, commonly known as NIS2.
Rather than focusing entirely on keeping attackers outside a network, Beelzebub works on the assumption that an intrusion may have already occurred. Its platform plants realistic decoy systems throughout an organisation’s infrastructure, creating opportunities to expose attackers before they reach genuine assets.
Turning Enterprise Infrastructure Into a Trap
Beelzebub’s technology belongs to a category of cybersecurity known as deception technology. Instead of waiting for malicious activity to trigger an alert on a production system, the platform creates convincing replicas of servers, databases, application programming interfaces, cloud environments and other infrastructure.
These decoys are designed to appear valuable to attackers while remaining isolated from real business systems. Because legitimate employees and applications should have little reason to interact with them, activity inside a decoy can provide a strong indication that an intruder is moving through the network.
The approach is intended to address one of the most difficult stages of a cyberattack: the period after an attacker gains initial access but before the final payload is deployed.
Attackers frequently spend time exploring systems, escalating privileges, collecting credentials and identifying valuable data. Beelzebub aims to interrupt that process by guiding suspicious activity towards controlled environments where it can be observed and contained.
The company says its traps use large language models to behave more like genuine infrastructure. They can generate realistic responses and adapt their behaviour, making it more difficult for an attacker to determine that they have entered a decoy.
An Automated Offence-and-Defence Loop
The platform combines three products designed to cover different stages of cybersecurity testing and incident response.
Arcangelo serves as the offensive component. It simulates targeted attacks against an organisation’s infrastructure, helping security teams identify weaknesses and test how their controls respond.
Beelzebub Managed forms the defensive layer. It distributes AI-powered traps across an organisation’s environment and monitors them for suspicious activity. When an attacker interacts with one of the decoys, the system can isolate the affected machine, block the activity and initiate predefined response actions.
The company describes this combination as an automated purple-team model. In cybersecurity, red teams typically simulate attackers, while blue teams defend systems. Purple-team operations attempt to bring the two functions together so that the results of offensive testing can directly improve defensive controls.
By connecting attack simulations with live deception systems, Beelzebub is attempting to reduce the handoffs that often occur between separate security tools, external consultants and internal teams.
The company says its traps can also be updated to reflect newly disclosed Common Vulnerabilities and Exposures. This allows the platform to imitate systems affected by emerging vulnerabilities and potentially attract attackers searching for those weaknesses.
AI-Assisted Malware Analysis
The third component, Caronte, is an AI-powered malware analysis system.
After malicious software is detected, Caronte can reverse-engineer the sample and produce an incident report describing its behaviour. The objective is to shorten the time between discovering an attack and understanding how it works.
Malware analysis is traditionally a specialised and time-consuming process. Analysts may need to inspect code, observe how a program behaves in a controlled environment and determine whether it communicates with external infrastructure or attempts to spread to other machines.
Beelzebub says Caronte automates parts of this work, allowing organisations to generate an initial assessment more quickly.
The system can be operated on-premise, which may be important for government agencies, regulated companies and enterprises that cannot upload potentially sensitive malware samples to third-party cloud services.
Beelzebub’s wider platform is available as software as a service or as an on-premise deployment. For organisations with stricter data requirements, the company can also provide hardware for running its large language model inference locally.
Building Around Live Threat Intelligence
Beelzebub says more than 60 independent security researchers contribute threat intelligence to the platform.
This network provides information about new malware, attack techniques and vulnerabilities as they emerge. The intelligence can then be used to update the platform’s decoys, attack simulations and analysis capabilities.
The company previously gained attention for documenting TeamPCP, a threat actor associated with attacks on cloud infrastructure and cryptojacking campaigns. TeamPCP has also been linked to a breach involving GitHub’s infrastructure.
Discovering and studying threat groups can provide cybersecurity vendors with practical information about how attackers behave after entering a network. That information can be used to design decoys that resemble the systems, credentials and services attackers are most likely to target.
Beelzebub’s technology is also available through an open-source community edition, giving researchers and security teams a way to experiment with its honeypot approach.
The open-source project supports multiple protocols and services, including Secure Shell, File Transfer Protocol, databases and web applications. This allows organisations to deploy decoys that resemble different parts of their infrastructure.
Responding to Faster, More Automated Attacks
The funding comes as generative AI and automation are changing both sides of cybersecurity.
Attackers can use AI tools to generate phishing messages, analyse software for vulnerabilities, modify malicious code and conduct operations across a larger number of targets. These capabilities do not eliminate the need for technical expertise, but they can allow smaller groups to operate at greater speed and scale.
Security teams are responding by introducing more automation into detection, investigation and incident response. Deception technology offers another layer by creating environments where attackers can be studied without exposing genuine data or systems.
Beelzebub founder and CEO Mario Candela argues that defensive tools must increasingly operate at machine speed to remain effective against automated attacks.
The company’s strategy is not to replace existing endpoint, network or identity security products. Instead, it attempts to add an internal detection layer for situations where an attacker has already bypassed perimeter defences.
This assumed-breach model has become more relevant as enterprise infrastructure expands across cloud platforms, remote devices, application programming interfaces and software supply chains. Protecting every possible entry point is difficult, making rapid detection inside the network increasingly important.
Why Deception Could Become a Core Cybersecurity Layer
As attackers increasingly use AI to automate reconnaissance, exploit vulnerabilities and adapt malware, deception technology could become a more important layer of enterprise defence. Instead of relying solely on perimeter controls, organisations can deploy realistic decoys that expose intruders after they enter a network and before they reach critical systems.
The strongest platforms will likely combine deception with continuous attack simulation and automated investigation. This could shorten the time between intrusion, detection and containment, while giving security teams clearer insight into an attacker’s tools, objectives and movement across the network.
Deception will not replace endpoint security, identity controls or vulnerability management, but it could make those systems more effective by providing high-confidence signals from activity that should never occur. Beelzebub’s challenge will be proving that its approach can operate reliably at enterprise scale without adding excessive complexity to already crowded security environments.












