- Target Sectors
- Critical Infrastructure, Energy, Oil and Gas, Electric Utilities, Manufacturing, ICS Vendors and Manufacturers
- Associated Malware
- TRITON (TRISIS, HatMan), WMImplant, Mimikatz, PsExec, cryptcat, SecHack
Overview
TEMP.Veles, also tracked by the alias XENOTIME, is a highly sophisticated and dangerous Russia-based threat group (G0088) with a demonstrated capability to compromise and disrupt industrial control systems (ICS), specifically safety instrumented systems (SIS). This group is primarily associated with the development and deployment of the TRITON (also known as TRISIS or HatMan) malware framework, which is specifically designed to manipulate industrial safety systems. The group’s origin is firmly attributed to Russia, with FireEye and the U.S. Treasury directly linking intrusion activity and TRITON development to the Russian government-owned Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM).
Their core motivation appears to be sabotage and destruction, aiming to cause physical damage, operational disruption, and potentially lead to loss of life. Unlike many financially motivated or pure espionage groups, TEMP.Veles has shown a clear intent to weaponize cyber capabilities for kinetic effects in industrial environments. Initially observed targeting oil and gas facilities, particularly in the Middle East, the group has expanded its targeting scope geographically and across sectors, including electric utilities in North America and other regions. They have also been observed compromising ICS vendors and manufacturers, indicating a potential for supply chain attacks.
Tactics & Techniques
TEMP.Veles employs a blend of common and highly specialized tactics, techniques, and procedures (TTPs) to achieve their objectives within critical infrastructure environments. Their initial access often involves social engineering tactics like watering hole websites or phishing emails to compromise industrial employees. They have also used compromised VPN accounts to gain entry.
Once inside a target network, TEMP.Veles focuses on establishing persistence and escalating privileges. They utilize scheduled tasks, sometimes employing XML triggers, and modify registry keys like HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options. For lateral movement and command and control (C2), they leverage Remote Desktop Protocol (RDP) through jump boxes, often using valid credentials, and secure channels like encrypted SSH-based tunnels for tool transfer and execution. The group also makes use of Virtual Private Server (VPS) infrastructure for their operations.
Credential harvesting is a significant part of their reconnaissance, employing tools like Mimikatz and a custom tool named SecHack. They have also shown ingenuity in capturing credentials by redirecting text-based login codes to attacker-controlled websites. Defense evasion techniques include modifying open-source tools such as cryptcat to reduce antivirus detection and routinely deleting tools, logs, and other files after use. They have also used timestomping to alter file metadata. Their ability to conduct detailed network reconnaissance against targets of interest is crucial for their operations, often utilizing publicly available tools like WMImplant. Critically, their attacks have exploited poorly configured operational technology (OT) firewalls to move into the ICS environment.
Notable Campaigns
The most significant and publicly recognized campaign attributed to TEMP.Veles is the TRITON Safety Instrumented System Attack in 2017. This incident targeted a petrochemical plant in Saudi Arabia and involved the deployment of the TRITON malware framework against Schneider Electric’s Triconex safety controllers. The malware attempted to manipulate the plant’s safety instrumented system (SIS), causing a safety trip that resulted in an automatic shutdown of the plant and disrupted operations for over a week. This attack was groundbreaking and alarming because TRITON was the first known malware specifically designed to target industrial safety systems with the explicit intent to cause physical damage and potentially loss of life, rather than just espionage or disruption of IT networks. The incident highlighted critical vulnerabilities in ICS security and the potential for devastating physical consequences from cyberattacks. Investigations revealed that the attackers had a deep knowledge of the Triconex infrastructure and processes.
Following this initial high-profile attack, reports in 2018 and 2019 indicated XENOTIME’s expansion of activities, including probing electric utility companies in the United States and Asia-Pacific. This suggested a shift in targeting beyond oil and gas to the broader electric utility sector, signaling preparation for future disruptive campaigns.
Associated Malware & Tools
TEMP.Veles is characterized by its sophisticated and dangerous arsenal of malware and tools, often combining custom-developed capabilities with modified open-source software:
- TRITON (TRISIS, HatMan): This is the group’s signature malware. It’s a highly specialized framework designed to communicate with and reprogram Triconex SIS controllers. TRITON allows attackers to send unauthorized commands, read and write programs, query controller states, and inject malicious function code. Its purpose is to disable or manipulate safety systems, potentially leading to unsafe conditions and physical damage.
- WMImplant: A publicly available PowerShell-based tool used for remote command execution and reconnaissance.
- Mimikatz: A well-known open-source tool frequently used for credential harvesting within compromised networks.
- PsExec: A legitimate Microsoft tool abused by threat actors for remote execution and lateral movement across systems.
- cryptcat: A modified version of this open-source networking utility has been used by TEMP.Veles, likely to encrypt their traffic and reduce detection rates.
- SecHack: A custom tool utilized for credential harvesting, demonstrating the group’s ability to develop bespoke malicious software.
The group’s proficiency in developing malware like TRITON, which requires intimate knowledge of industrial safety protocols and specific hardware, underscores their advanced capabilities.
Current Status
TEMP.Veles (XENOTIME) remains an active and evolving threat. Dragos, an industrial cybersecurity firm, has indicated that the group continues to operate globally, expanding its targeting beyond its initial focus on oil and gas to include the electric utility sector, and has been active since at least 2014. Reports from 2019 highlighted the group’s reconnaissance activities against electric utilities in the United States and Asia-Pacific, suggesting ongoing preparatory work for future operations.
Most recently, in March 2022, the FBI issued a warning reaffirming that the Russian Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM), linked to the TRITON malware, continues to conduct activities targeting the global energy sector. This warning coincided with a U.S. indictment of a Russian national and TsNIIKhM employee involved in the 2017 TRITON attack, reinforcing the ongoing nature and state-sponsored backing of this threat actor. The MITRE ATT&CK entry for G0088 was last modified in April 2024, indicating continued relevance and monitoring of the group’s profile. Analysis from February 2026 also refers to TRITON malware as an evolving threat that requires continuous vigilance. These reports collectively confirm that TEMP.Veles continues to pose a critical and active risk to global industrial infrastructure.
Related content
Cleaver (G0003): Iranian APT Targeting Critical Infrastructure
Adversary ProfileCarbanak Threat Profile: Financial Apex Predators
Adversary ProfileThreat Actor Profile: Dragonfly (G0035) – Russia’s Critical Infrastructure Espionage Group
Adversary ProfileBRONZE BUTLER (G0060) Threat Profile: Persistent Chinese Cyber Espionage
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call