XENOTIME, also known as TEMP.Veles, is an industrial-control-system-focused threat actor best known for the TRISIS/TRITON attack against a Saudi petrochemical facility in 2017. The group is widely associated with Russian state interests and has been linked in public reporting to Russian government entities. XENOTIME is notable for demonstrating the ability to move from enterprise IT networks across segmented environments into operational technology and safety instrumented system environments, culminating in attempts to modify industrial controller logic and create unsafe or disruptive conditions. The actor initially drew attention for targeting Triconex safety instrumented systems and for malware and tooling associated with TRISIS/TRITON. Its operations have shown a full intrusion chain that includes reconnaissance, compromise of IT environments, traversal of demilitarized zones, access to engineering workstations, and manipulation of industrial control components. XENOTIME has also been reported compromising ICS vendors and manufacturers, creating supply-chain risk beyond direct victim targeting. Since 2018, XENOTIME activity has expanded beyond the Middle East to include oil and gas organizations in Europe, the United States, and Australia. Reporting also places the group in research and reconnaissance activity against liquefied natural gas entities in Europe and the United States, including Dutch LNG infrastructure. Victimology consistently centers on industrial infrastructure, especially oil and gas, LNG, and related manufacturing and ICS ecosystem organizations. Observed tradecraft includes extensive reconnaissance; use of PowerShell for execution and timestomping; scheduled tasks for persistence or execution; masquerading files as legitimate software, including industrial vendor software and Windows update artifacts; and deletion of tools, logs, and other files for cleanup and anti-forensics. Public ATT&CK-style mappings also associate the group with DNS-based command and control and PowerShell execution. XENOTIME is regarded as one of the most significant OT threat actors because it has demonstrated intent and capability aligned with disruptive or destructive effects in industrial environments, particularly where safety systems are involved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Known for targeting safety instrumented systems in petrochemical environments, moving from IT into OT networks and modifying controller logic; also associated with firmware-level impact scenarios.
Known for attacking industrial safety instrumented systems in an OT environment, specifically Schneider Electric Triconex, in a sabotage-oriented operation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.