Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TEMP.Veles

Also known as: XENOTIME, Triton, TRISIS, G0088, ATK91

Description

TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.(Citation: FireEye TRITON 2019)(Citation: FireEye TEMP.Veles 2018)(Citation: FireEye TEMP.Veles JSON April 2019)

Goals & Targeting

Targeted Sectors

Energy

AI Analysis

· 1 week ago

Executive Summary

TEMP.Veles, also known as XENOTIME, Triton, or TRISIS, is a Russia-based threat group known for targeting critical energy infrastructure. They primarily conduct espionage activities using the TRITON malware framework to manipulate industrial control systems (ICS), posing significant risks to global energy security.

Goals & Targeting

TEMP.Veles' strategic objectives center on espionage, targeting energy sector entities that operate critical infrastructure. Their focus on industrial systems suggests an intent to disrupt or gain control over processes vital to national stability. By compromising ICS, they can potentially alter operational parameters, leading to significant physical and economic damage.

Enhanced Description

TEMP.Veles represents a sophisticated cyber Threat Actor with a focus on compromising industrial control systems, particularly within the energy sector. Known for deploying TRITON malware, they have demonstrated the capability to infiltrate critical infrastructure, potentially causing physical damage alongside data breaches. Linked to Russian state-sponsored activities, TEMP.Veles' operations underscore the vulnerabilities in ICS environments and highlight the intersection of cyber threats with national security.

Key Capabilities

  • Advanced persistent threat (APT) group
  • TRITON malware deployment for ICS manipulation
  • State-sponsored espionage activities

MITRE ATT&CK Tactics

Espionage
Disruption

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

TRITON malware
Custom ICS-targeted tools

Campaigns & Victims

TEMP.Veles has been active since at least 2018, with notable campaigns targeting energy companies. Their operations have featured spear-phishing attacks and sophisticated malware deployment to compromise ICS. Notable incidents include attempts to infiltrate TRITON into systems, which could lead to operational disruption or sabotage.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Malicious payload delivery via email
  • C2 infrastructure for ICS manipulation

Recommended Actions

  • Implement robust security measures around industrial control systems
  • Conduct regular threat hunting for ICS-specific attacks
  • Monitor network traffic for anomalies indicative of APT activity

Suggested Tags

APT
espionage
critical-infrastructure
energy-sector

Confidence Assessment

High confidence based on credible reports from FireEye and others. Gaps include specific attack details and exact TTPs beyond known incidents.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Dragos Xenotime 2018 — Dragos, Inc.. (n.d.). Xenotime. Retrieved April 16, 2019.
  2. FireEye TEMP.Veles 2018 — FireEye Intelligence . (2018, October 23). TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers. Retrieved April 16, 2019.
  3. FireEye TRITON 2019 — Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019.
  4. FireEye TEMP.Veles JSON April 2019 — Miller, S., et al. (2019, April 10). TRITON Appendix C. Retrieved April 29, 2019.
  5. Pylos Xenotime 2019 — Slowik, J.. (2019, April 12). A XENOTIME to Remember: Veles in the Wild. Retrieved April 16, 2019.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
cyber_espionage
critical_infrastructure
energy_sector
ICS_attacks

Details

MITRE ID
G0088
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--9538b1a4-4120-4e2d-bf59-3b11fcab05a4
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.