TEMP.VELES
G0088
RUSSIA
XENOTIME
Threat IntelligenceAPTRussiaApril 15, 2025

TEMP.Veles Threat Profile

Russian group behind TRITON/TRISIS malware targeting Schneider Electric Triconex safety systems, capable of causing physical destruction.

Russian group behind TRITON/TRISIS malware targeting Schneider Electric Triconex safety systems, capable of causing physical destruction. This profile is mapped to MITRE ATT&CK G0088 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

TEMP.Veles (also tracked as XENOTIME) is a threat group attributed to Russia. The group primarily targets Industrial control systems, petrochemical for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0088 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with TEMP.Veles include:

Targeting & Operations

TEMP.Veles operations focus on Industrial control systems, petrochemical. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the Industrial control systems sector should treat TEMP.Veles as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in TEMP.Veles operations:

Technique IDTechnique NameTactical Context
T1059.006T1059.006Observed in TEMP.Veles campaigns
T1078T1078Observed in TEMP.Veles campaigns
T1071.001T1071.001Observed in TEMP.Veles campaigns
T1562.001T1562.001Observed in TEMP.Veles campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0088/

Notable Campaigns

This threat group has been active in operations targeting Industrial control systems, petrochemical. Security researchers have documented campaigns involving TRITON/TRISIS and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to Russia-nexus operations.

Detection & Defense

Recommended defensive measures against TEMP.Veles:

How Mjolnir Security Can Help

Defend Against TEMP.Veles

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against Russia-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: April 15, 2025