TEMP.Veles

MITRE ATT&CK: G0088 View on attack.mitre.org

Aliases: XENOTIME, Xenotime, ATK91, TEMP.Veles

Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:57:35

Targeted industries: energy-and-utilities

Context

TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.

Detection coverage

  • 7 YARA rules

Malware & tools used

  • Triton (malware)
  • Supply Chain Compromise (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Mimikatz (malware)
  • PsExec (malware)

Reports & references

  • Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools.Html (report)
  • dragos.com — Trisis Analyzing Safety System Targeting Malware (report)
  • Mandiant — Attackers Deploy New Ics Attack Framework Triton (report)
  • MITRE ATT&CK — G0088 (report)
  • cyberthreat.thalesgroup.com — Atk91 (report)
  • dragos.com — Xenotime (report)
  • dragos.com — Xenotime (report)
  • pylos.co — A Xenotime To Remember Veles In The Wild (report)
  • Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools (report)
  • Mandiant — Triton Actor Ttp Profile Custom Attack Tools Detections (report)
  • Mandiant — Triton Appendix C (report)

Attributed from

  • C0032 (campaign)
  • Triton Safety Instrumented System Attack (campaign)

External references