← Back to all threat actors

TEMP.Veles

Also known as XENOTIME
Tracked as G0088

TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: XENOTIME

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0088

Reviewed identity mapping approved on this date.

Last observed
CampaignTriton Safety Instrumented System Attack

Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical org…

Last observed
CampaignC0032

C0032 was an extended campaign suspected to involve the Triton adversaries with related capabilities and techniques focused on gaining a foothold within IT environments. This campaign occurred…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

TEMP.VelesCanonical Name
XENOTIMEAlias
G0088Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...