Also known as: XENOTIME, Triton, TRISIS, G0088, ATK91
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.(Citation: FireEye TRITON 2019)(Citation: FireEye TEMP.Veles 2018)(Citation: FireEye TEMP.Veles JSON April 2019)
Targeted Sectors
Executive Summary
TEMP.Veles, also known as XENOTIME, Triton, or TRISIS, is a Russia-based threat group known for targeting critical energy infrastructure. They primarily conduct espionage activities using the TRITON malware framework to manipulate industrial control systems (ICS), posing significant risks to global energy security.
Goals & Targeting
TEMP.Veles' strategic objectives center on espionage, targeting energy sector entities that operate critical infrastructure. Their focus on industrial systems suggests an intent to disrupt or gain control over processes vital to national stability. By compromising ICS, they can potentially alter operational parameters, leading to significant physical and economic damage.
Enhanced Description
TEMP.Veles represents a sophisticated cyber Threat Actor with a focus on compromising industrial control systems, particularly within the energy sector. Known for deploying TRITON malware, they have demonstrated the capability to infiltrate critical infrastructure, potentially causing physical damage alongside data breaches. Linked to Russian state-sponsored activities, TEMP.Veles' operations underscore the vulnerabilities in ICS environments and highlight the intersection of cyber threats with national security.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TEMP.Veles has been active since at least 2018, with notable campaigns targeting energy companies. Their operations have featured spear-phishing attacks and sophisticated malware deployment to compromise ICS. Notable incidents include attempts to infiltrate TRITON into systems, which could lead to operational disruption or sabotage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence based on credible reports from FireEye and others. Gaps include specific attack details and exact TTPs beyond known incidents.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
0
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics