TEMP.Veles — APT Profile
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
XENOTIME, G0088, ATK91
Tools & malware
Vendor research
- TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping Miller, S, et al
- TRITON Appendix C Miller, S., et al
- TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers FireEye Intelligence
- Xenotime Dragos, Inc.
- A XENOTIME to Remember: Veles in the Wild Pylos Xenotime
- TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping FireEye
- . (n.d.). Xenotime Dragos
- TRITON Appendix C FireEye
- TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers FireEye
Countries linked to this actor
- Saudi Arabia targets