Threat Advisory

New Hacktivist Group Twelve Targets Russian Infrastructure with Attacks

Threat: Malicious Campaign
Threat Actor Name: Twelve
Threat Actor Type: Hacktivist
Targeted Region: Russia
Targeted Sector: Technology & IT, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Twelve threat group emerged in the context of the ongoing Russian-Ukrainian conflict and has primarily targeted Russian government organizations. Their modus operandi is characterized by encrypting and then deleting victims’ data, which severely complicates recovery efforts. This group has been linked to previous incidents involving the exfiltration of sensitive information, which they disseminate on Telegram. Notably, twelve has exploited vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access to target systems. Their activities suggest a persistent threat, with indications that they may soon resurface after a period of inactivity.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Twelve threat group emerged in the context of the ongoing Russian-Ukrainian conflict and has primarily targeted Russian government organizations. Their modus operandi is characterized by encrypting and then deleting victims’ data, which severely complicates recovery efforts. This group has been linked to previous incidents involving the exfiltration of sensitive information, which they disseminate on Telegram. Notably, twelve has exploited vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access to target systems. Their activities suggest a persistent threat, with indications that they may soon resurface after a period of inactivity.[emaillocker id="1283"]

Twelve’s attack strategy follows the Unified Kill Chain methodology, moving through stages that include external reconnaissance, initial compromise, lateral movement, and the final destruction of targeted systems. The group relies heavily on publicly available tools like Cobalt Strike, mimikatz, and BloodHound to gain access and control over compromised networks. Twelve typically infiltrates target organizations through third-party contractors, exploiting VPN, RDP, and SSH protocols to access the internal network. They have been known to exploit vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access. Once inside, they deploy web shells, backdoors, and perform data exfiltration using techniques like PowerShell scripts and scheduled tasks. Additionally, the group uses ransomware compiled from open-source code, as well as wipers that overwrite and erase data irretrievably, affecting the infrastructure’s master boot record (MBR) and disrupting future system functionality.

Twelve's activities demonstrate a clear focus on hacktivism rather than financial gain, prioritizing the infliction of damage over ransom demands. Their reliance on common malware tools indicates a lower barrier to detection, offering organizations the opportunity to bolster defenses against their tactics. The group's exploitation of vulnerabilities such as CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload further emphasizes the need for organizations to stay vigilant. However, failure to implement adequate measures could result in substantial damage to infrastructure. Vigilance and proactive security practices are essential to mitigate the risks posed by this evolving threat actor.
THREAT PROFILE:

Tactic Technique Id Technique
 Reconnaissance T1595 Active Scanning
Execution T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
Persistence T1136 Create Account
Privilege Escalation T1548 Abuse Elevation Control Mechanism
Defense Evasion T1078 Valid Accounts
T1134 Access Token Manipulation
T1055 Process Injection
 T1027 Obfuscated Files or Information
 T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
Discovery  T1046 Network Service Discovery
T1018 Remote System Discovery
 T1135 Network Share Discovery
Lateral Movement  T1210 Exploitation of Remote Services
Collection T1213 Data from Information Repositories
T1005 Data from Local System
Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1486 Data Encrypted for Impact
T1561 Disk Wipe
T1489 Service Stop

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/09/hacktivist-group-twelve-targets-russian.html

[/emaillocker]
crossmenu