Friday, April 18, 2025
HomeCyber Security NewsHacktivist Groups Operating Together! Connection Ober TTPs Uncovered

Hacktivist Groups Operating Together! Connection Ober TTPs Uncovered

Published on

SIEM as a Service

Follow Us on Google News

Cybersecurity experts have uncovered a significant connection between hacktivist groups BlackJack and Twelve through overlapping tactics, techniques, and procedures (TTPs).

This discovery illuminates the sophisticated methods employed by these groups and raises questions about their potential collaboration or shared objectives.

The findings reveal shared tools, malware, and similar attack patterns targeting Russian organizations.

- Advertisement - Google News

This article delves into the details of the investigation, exploring the implications of these connections and what they mean for cybersecurity defenses.

Who are BlackJack and Twelve?

BlackJack

BlackJack emerged at the end of 2023 as a hacktivist group targeting Russian companies and government institutions.

Their stated goal, as communicated via their Telegram channel, is to exploit vulnerabilities within Russian networks.

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try It for Free

By June 2024, BlackJack had claimed responsibility for over a dozen attacks, with additional unpublicized incidents suggesting their involvement.

The group relies on freely available and open-source software, such as the SSH client PuTTY and the wiper Shamoon, indicating a lack of resources typical of more sophisticated APT groups.

Contents of the LockBit ransom note
Contents of the LockBit ransom note

Twelve

The Twelve group shares many similarities with BlackJack regarding tools and targets. Like BlackJack, Twelve utilizes publicly available software for attacks, avoiding proprietary tools.

The overlap between these two groups was discovered through Kaspersky Security Network (KSN) telemetry and Kaspersky Threat Intelligence solutions, revealing shared malware samples and attack methodologies.

Overlapping Tactics and Tools

According to the SecureList report, both BlackJack and Twelve have been found using similar versions of the Shamoon wiper and LockBit ransomware.

The Shamoon wiper used by BlackJack is written in Go, while Twelve’s version also exhibits similar characteristics. These malware samples were found in identical directories across different attacks:

  • Sysvol\domain\scripts
  • \$$DOMAIN]\netlogon\
  • C:\ProgramData\

These specific directories allow attackers to spread malware efficiently across victim infrastructures.

Remote Access Tools

Both groups employ remote access tools (RATs) to maintain persistent access to compromised systems.

BlackJack initially attempted to use Radmin but ultimately relied on AnyDesk for external connections. Similarly, Twelve uses tools like PuTTY for SSH connections within targeted infrastructures.

Shared Commands and Procedures

The investigation revealed identical commands used by both groups for creating scheduled tasks and clearing event logs.

These commands highlight a systematic approach to executing attacks while maintaining stealth:

# Scheduled Task Creation

reg:\\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ID}:Actions","`powershell.exe` Copy-Item `\\[DOMAIN]\netlogon\bj.exe` -Destination `C:\ProgramData`

# Clearing Event Logs

powershell -command wevtutil el | Foreach-Object {Write-Host Clearing $_; wevtutil cl $_}

The significant overlap in TTPs between BlackJack and Twelve suggests collaboration or a shared objective against Russian targets.

While direct attribution remains challenging, the similarities in malware samples, attack methodologies, and target selection point towards a unified cluster of hacktivist activity.

Impact on Targeted Organizations

These groups’ activities have primarily affected Russia’s government, telecommunications, and industrial sectors.

Their attacks focus on causing maximum damage by encrypting, deleting, and stealing data rather than seeking financial gain.

The discovery of overlapping TTPs between BlackJack and Twelve underscores the evolving landscape of cyber threats posed by hacktivist groups.

Organizations must bolster their cybersecurity defenses to mitigate potential risks as these groups continue to refine their methods and collaborate on tactics.

Understanding the connections between seemingly disparate threat actors can provide valuable insights into their strategies and help develop more effective countermeasures.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Registration

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...

Microsoft Vulnerabilities Reach Record High with Over 1,300 Reported in 2024

The 12th Edition of the Microsoft Vulnerabilities Report has revealed a significant surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...