-=TWELVE=- is back


In the spring of 2024, posts with real people’s personal data began appearing on the -=TWELVE=- Telegram channel. Soon it was blocked for falling foul of the Telegram terms of service.

The group stayed off the radar for several months, but as Kaspersky researchers investigated a late June 2024 attack, they found that it employed techniques identical to those of Twelve and relied on C2 servers linked to the threat actor. Kaspersky researchers are therefore confident that the group is still active and will probably soon resurface. This article uses the Unified Kill Chain methodology to analyze the attackers’ actions.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products

    September 15, 2026

    Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history. While this CVE count is hardly notable compared to some vendors – hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month – it does set a company record for ...

  • Iranian Cyber Targeting of Dissidents, Activists and Journalists

    September 15, 2026

    CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost ...

  • ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 14, 2026

    If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a ...

  • OpenAI’s malicious bot swarm attacked RubyGems

    September 14, 2026

    OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May ...

  • Revolut confirms customer data breach through fake government requests

    September 12, 2026

    British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including ...

  • The modern bank heist is already under way

    September 11, 2026

    The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, says Tom Kellermann, VP of AI Security and Threat Research at Trend AI. The objective is no longer ...