XENOTIME, also tracked as TEMP.Veles, is a Russia-linked threat actor associated with the TRITON/TRISIS malware (also called HatMan) used in the 2017 attack on Schneider Electric Triconex safety instrumented systems at a petrochemical/oil and gas facility in the Middle East. The content states that the U.S. government linked activity surrounding the TRITON intrusion to the Russian government-owned Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM), and that TsNIIKhM was later sanctioned by the U.S. Treasury for its connection to Triton malware. The group is described as highly capable and dangerous in industrial control system environments. Reported activity shows XENOTIME moving from enterprise IT networks across DMZs into OT environments, reaching engineering workstations and modifying controller logic. Beyond the 2017 TRITON incident, Dragos identified reconnaissance and potential initial access activity by XENOTIME against North American and APAC electric utility networks in early 2019, including activity affecting at least 20 U.S. electric utilities. The content also states that the group compromised several ICS vendors and manufacturers, creating a potential supply-chain threat. Observed tradecraft in campaign C0032 and the Triton Safety Instrumented System Attack includes use of compromised VPN accounts, VPS infrastructure, RDP, encrypted SSH-based tunnels, and port-protocol mismatches on ports 443, 4444, 8531, and 50501 for command and control. The actor used publicly available and administrative tools including Mimikatz, PsExec, WMImplant, and other open-source software. It used PowerShell, including for timestomping, modified NTFS $STANDARD_INFORMATION timestamps on tools, installed scheduled tasks defined in XML files, and routinely deleted tools, logs, and other files after use. The content also notes use of cryptcat binaries to encrypt traffic. Known aliases in the provided content are XENOTIME and TEMP.Veles.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Known for targeting safety instrumented systems in petrochemical environments, moving from IT into OT networks and modifying controller logic; also associated with firmware-level impact scenarios.
Known for attacking industrial safety instrumented systems in an OT environment, specifically Schneider Electric Triconex, in a sabotage-oriented operation.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Used timestomping during the C0032 campaign to alter NTFS metadata on tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.