TEMP.Veles is a threat actor designation observed in the C0032 campaign. The provided content attributes to TEMP.Veles a consistent post-operation cleanup behavior: it routinely deleted tools, logs, and other files from victim systems after they were no longer needed. This indicates anti-forensic and defense-evasion tradecraft focused on removing operational artifacts and reducing forensic visibility. No additional high-confidence details are provided in the content regarding malware family type, infection vector, specific payloads, targeted industries, platforms, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tooling used in the C0032 campaign that routinely deletes tools/logs/files after use (post-operation cleanup).
Malware/tooling associated with routine deletion of tools/logs after use (cleanup/anti-forensics).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.