EXECUTIVE SUMMARY
The Twelve threat group emerged in the context of the ongoing Russian-Ukrainian conflict and has primarily targeted Russian government organizations. Their modus operandi is characterized by encrypting and then deleting victims’ data, which severely complicates recovery efforts. This group has been linked to previous incidents involving the exfiltration of sensitive information, which they disseminate on Telegram. Notably, twelve has exploited vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access to target systems. Their activities suggest a persistent threat, with indications that they may soon resurface after a period of inactivity.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The Twelve threat group emerged in the context of the ongoing Russian-Ukrainian conflict and has primarily targeted Russian government organizations. Their modus operandi is characterized by encrypting and then deleting victims’ data, which severely complicates recovery efforts. This group has been linked to previous incidents involving the exfiltration of sensitive information, which they disseminate on Telegram. Notably, twelve has exploited vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access to target systems. Their activities suggest a persistent threat, with indications that they may soon resurface after a period of inactivity.[emaillocker id="1283"]
Twelve’s attack strategy follows the Unified Kill Chain methodology, moving through stages that include external reconnaissance, initial compromise, lateral movement, and the final destruction of targeted systems. The group relies heavily on publicly available tools like Cobalt Strike, mimikatz, and BloodHound to gain access and control over compromised networks. Twelve typically infiltrates target organizations through third-party contractors, exploiting VPN, RDP, and SSH protocols to access the internal network. They have been known to exploit vulnerabilities in the vSphere virtualization platform, specifically CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload, to gain initial access. Once inside, they deploy web shells, backdoors, and perform data exfiltration using techniques like PowerShell scripts and scheduled tasks. Additionally, the group uses ransomware compiled from open-source code, as well as wipers that overwrite and erase data irretrievably, affecting the infrastructure’s master boot record (MBR) and disrupting future system functionality.
Twelve's activities demonstrate a clear focus on hacktivism rather than financial gain, prioritizing the infliction of damage over ransom demands. Their reliance on common malware tools indicates a lower barrier to detection, offering organizations the opportunity to bolster defenses against their tactics. The group's exploitation of vulnerabilities such as CVE-2021-21972 remote code execution and CVE-2021-22005 arbitrary file upload further emphasizes the need for organizations to stay vigilant. However, failure to implement adequate measures could result in substantial damage to infrastructure. Vigilance and proactive security practices are essential to mitigate the risks posed by this evolving threat actor.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1595 | Active Scanning |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Persistence | T1136 | Create Account |
| Privilege Escalation | T1548 | Abuse Elevation Control Mechanism |
| Defense Evasion | T1078 | Valid Accounts |
| T1134 | Access Token Manipulation | |
| T1055 | Process Injection | |
| T1027 | Obfuscated Files or Information | |
| T1070 | Indicator Removal | |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1046 | Network Service Discovery |
| T1018 | Remote System Discovery | |
| T1135 | Network Share Discovery | |
| Lateral Movement | T1210 | Exploitation of Remote Services |
| Collection | T1213 | Data from Information Repositories |
| T1005 | Data from Local System | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
| T1561 | Disk Wipe | |
| T1489 | Service Stop |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/09/hacktivist-group-twelve-targets-russian.html