WMImplant is a publicly available PowerShell-based tool used for lateral movement. The provided content states that TEMP.Veles used WMImplant during activity associated with the TRITON intrusion, which impacted industrial control systems at a critical infrastructure facility. In 2017, TEMP.Veles reportedly experienced execution issues with WMImplant on victim systems, potentially due to antivirus detection; after those issues, a customized WMImplant utility was evaluated in a malware testing environment and then re-attempted on a compromised system the next day. The content further characterizes TEMP.Veles custom payloads as weaponized versions of legitimate open-source software retrofitted with command-and-control code, but does not explicitly state that WMImplant itself was modified in that way beyond noting a customized variant. High-confidence associations in the content are therefore that WMImplant is PowerShell-based, publicly available, used for lateral movement, and linked to TEMP.Veles activity in the TRITON/ICS intrusion context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TEMP.Veles’ lateral movement activities used a publicly-available PowerShell-based tool, WMImplant.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Public PowerShell-based lateral movement utility; the actor appears to have customized and tested it to improve execution and evade AV in victim environments.
PowerShell-based WMI lateral movement utility; TEMP.Veles used and customized it, apparently to improve execution and evade AV detection.
Publicly available PowerShell-based post-exploitation tool used by TEMP.Veles.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.