Hacker groupG0088

TEMP.Veles

Also tracked as XENOTIME

TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.

Known attack methods
0
Origin
Russia
First seen
2014
Last seen
2017-08
Source
MITRE ATT&CK

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

MimikatzPsExec

Campaigns

C0032Triton Safety Instrumented System Attack