TEMP.Veles
MITRE ATT&CK: G0088 View on attack.mitre.org
Aliases: XENOTIME, Xenotime, ATK91, TEMP.Veles
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:57:35
Targeted industries: energy-and-utilities
Context
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.
Detection coverage
- 7 YARA rules
Malware & tools used
Reports & references
- Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools.Html (report)
- dragos.com — Trisis Analyzing Safety System Targeting Malware (report)
- Mandiant — Attackers Deploy New Ics Attack Framework Triton (report)
- MITRE ATT&CK — G0088 (report)
- cyberthreat.thalesgroup.com — Atk91 (report)
- dragos.com — Xenotime (report)
- dragos.com — Xenotime (report)
- pylos.co — A Xenotime To Remember Veles In The Wild (report)
- Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools (report)
- Mandiant — Triton Actor Ttp Profile Custom Attack Tools Detections (report)
- Mandiant — Triton Appendix C (report)
Attributed from
- C0032 (campaign)
- Triton Safety Instrumented System Attack (campaign)