Twelve is a hacktivist threat actor that emerged in April 2023 in the context of the Russia-Ukraine conflict and has primarily targeted Russian organizations, especially government entities. The group is known for destructive intrusions that combine data theft, public exposure of stolen information, ransomware-style encryption, and subsequent wiping intended to maximize operational damage and hinder recovery. Its activity indicates a sabotage-oriented model rather than conventional profit-driven ransomware operations. Twelve commonly gains initial access through valid local or domain accounts, as well as stolen VPN or SSH certificates, including by first compromising contractors and then abusing trusted access into customer environments. The group has also been linked to scanning for internet-exposed remote access services and applications. After entry, it uses publicly available offensive tooling for reconnaissance, credential access, privilege escalation, lateral movement, and command and control. Reported tooling includes Cobalt Strike, mimikatz, BloodHound, PowerView, adPEAS, CrackMapExec, PsExec, chisel, ngrok, and network-scanning utilities. Lateral movement has frequently relied on RDP, SMB-based remote execution, and PowerShell remoting. For persistence and post-exploitation, Twelve has used PHP web shells on compromised web servers, manipulated Active Directory users, groups, and ACLs with PowerShell and native utilities, and attempted domain-wide malware deployment through scheduled tasks and Group Policy changes. In at least one case, the group exploited VMware vSphere vulnerabilities CVE-2021-21972 and CVE-2021-22005 to compromise vCenter and deploy the FaceFish backdoor. Defense evasion has included masquerading malware and scheduled tasks as legitimate software or services, clearing Windows event logs, and removing forensic artifacts such as RDP history and recent execution traces. Credential theft and collection are central to Twelve’s operations. The group has dumped credentials from LSASS, extracted Active Directory credential material including NTDS data and registry hives, and used password-recovery software to harvest additional secrets from compromised systems. It has also collected sensitive victim data including financial documents, technical materials, corporate communications, and messaging-session data, then archived and exfiltrated that information for later publication. For impact, Twelve has deployed ransomware variants derived from LockBit 3.0 source code and also used builds associated with Chaos. Encryption has been distributed broadly across victim environments via administrative shares, PowerShell, scheduled tasks, and Group Policy. Unlike financially motivated ransomware actors, Twelve’s ransom artifacts reportedly lacked meaningful negotiation channels. The group has also deployed Shamoon-like wipers that overwrite file contents and the master boot record, rendering systems unbootable and frustrating restoration efforts. This encrypt-then-wipe pattern is a defining characteristic of the actor. Twelve has conducted hack-and-leak operations through a Telegram presence used to publicize compromises and release stolen data. Researchers have identified substantial overlaps in infrastructure, tooling, and tradecraft between Twelve and other Russia-targeting clusters including Head Mare, BlackJack, Crypt Ghouls, and DARKSTAR, also known as COMET or Shadow. Shared use of malware, loaders, tunneling tools, credential-harvesting utilities, and command-and-control infrastructure suggests collaboration, shared resources, or participation in a broader pro-Ukrainian hacktivist ecosystem targeting Russian state and private-sector organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
An incident we investigated involved the FaceFish backdoor, loaded with the help of a web shell installed on a VMware vCenter server by exploiting the CVE-2021-21972 and CVE-2021-22005 vulnerabilities in the vSphere virtualization platform. The former vulnerability can be found in the platform’s client and allows remote code execution.
An incident we investigated involved the FaceFish backdoor, loaded with the help of a web shell installed on a VMware vCenter server by exploiting the CVE-2021-21972 and CVE-2021-22005 vulnerabilities in the vSphere virtualization platform. ... the latter is an arbitrary file upload vulnerability in the server.
47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group active against Russian organizations, motivated by disruption and public pressure.
Group linked by overlap with Crypt Ghouls through use of XenAllPasswordPro and the Intellpui.vbs loader for CobInt.
Hacktivist destructive operations against Russian government organizations, combining data theft, ransomware-style encryption, and wiper deployment to maximize disruption rather than pursue ransom payments.
Activity cluster whose tooling/C2 overlaps with Head Mare in operations targeting Russian entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.