Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationstate-sponsored-disruptioncredential-access-methodlateral-movement-method

Twelve Used Stolen Access, Ransomware, and Wipers Against Russian Targets

Updated 8d agoFirst seen May 21, 20262 sources

Threat actor Twelve, a hacktivist group that emerged during the Russian-Ukrainian conflict, has continued targeting Russian government organizations with intrusions that progress from stolen access to data theft, ransomware deployment, and destructive wiping. Researchers linked a late June 2024 attack to the group through matching tactics, techniques, procedures, and command-and-control infrastructure, indicating Twelve remained active even after its Telegram channel was blocked for publishing personal data. The group commonly gains entry through valid accounts, VPN access, or SSH certificates, sometimes by first compromising contractors connected to the ultimate target.

Once inside, Twelve uses tools including RDP, PowerShell, ngrok, Cobalt Strike, and mimikatz for lateral movement, privilege escalation, credential theft, and evasion. It has also deployed PHP web shells and exploited VMware vSphere flaws CVE-2021-21972 and CVE-2021-22005 to install the FaceFish backdoor on vCenter servers. For impact, the group exfiltrates sensitive data such as Telegram session information, uploads archives to DropMeFiles, encrypts systems with LockBit 3.0- and Chaos-based ransomware variants, and then distributes Shamoon-like wipers through Group Policy and scheduled tasks, underscoring an operation focused on sabotage and reputational damage rather than ransom payments.

Share:
Twelve Used Stolen Access, Ransomware, and Wipers Against Russian Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 21, 20261mo ago

Late June 2024 attack linked to Twelve

Researchers linked an attack in late June 2024 to Twelve based on matching tactics, techniques, procedures, and command-and-control infrastructure, indicating the group remained active after its Telegram channel was blocked.

Twelve: from initial compromise to ransomware and wipers | Securelist

Twelve's Telegram channel is blocked after doxxing posts

In spring 2024, Twelve's Telegram channel was blocked for posting personal data, according to the report.

Twelve: from initial compromise to ransomware and wipers | Securelist

Hacktivist group Twelve forms amid Russian-Ukrainian conflict

Securelist reported that Twelve was formed in April 2023 as a hacktivist group that primarily targeted Russian government organizations.

Twelve: from initial compromise to ransomware and wipers | Securelist
Jan 24, 20242y ago

Dropbox reports repeated-token extraction flaw to OpenAI

Dropbox disclosed that on January 24, 2024 it reported a repeated-token training data extraction vulnerability affecting OpenAI chat completion models including GPT-3.5 and GPT-4. OpenAI confirmed the GPT-3.5 and GPT-4 issues as vulnerabilities and later patched them by expanding filtering to multi-token repeats and adding server-side timeouts.

Bye Bye Bye...: Evolution of repeated token attacks on ChatGPT models - Dropbox
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.