NEW: Group Profiler — instant APT intel lookup. Try it →

TEMP.Veles

Also known as: XENOTIME

Overview

TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.

Naming & attribution

TEMP.Veles is tracked under 2 names across the industry. It uses 0 documented ATT&CK techniques — more than 0% of the 174 groups tracked here. Activity attributed since 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
XENOTIMEDragos, Inc.
TEMP.VelesMiller, S, et al

Capabilities

  • Documented tooling: TRISIS, custom credential harvesting — MISP galaxy (meta.capabilities)

Tools & malware (2)

Mimikatz · PsExec

Reporting (3)