Threats · Activity group
XENOTIME
Executive summary
XENOTIME is the Dragos activity group associated with the TRITON / TRISIS intrusion, in which malware was written to interact with Schneider Electric Triconex safety instrumented systems at a petrochemical facility. It is the only publicly reported activity group whose capability was aimed directly at a safety instrumented system.
Publicly associated reporting tracks closely related activity as TEMP.Veles. Subsequent reporting has described interest in electric utilities in North America and elsewhere, expanding the sector concern beyond oil and gas.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- TEMP.VelesAssociated activityHigh
Tracked by Google Threat Intelligence / Mandiant
- TRITON / TRISISCapability / malware nameConfirmed
Tracked by Mandiant / Dragos — Malware naming, not an actor alias.
- HatManCapability / malware nameConfirmed
Tracked by CISA
Relevance
Why OT defenders care
Objectives
- Interaction with safety instrumented systems
- Capability development against safety controllers
- Persistent access to process environments
Reported impacts
- Safety controllers entered a failsafe state and tripped the plant
- Loss of safety function was the assessed potential outcome
Observed behaviours
- Long dwell in the IT and DMZ environments before reaching the safety network
- Use of an engineering workstation as the pivot to the safety controller
- Direct interaction with safety controller programming over the vendor protocol
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- TRITON / TRISISFramework that reimplemented the TriStation protocol to reach safety controller firmware.
- Custom backdoors and credential tools
Commercial tool
Not publicly established
Open-source utility
Not publicly established
Native OS tool
- Native Windows administration tooling
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- 2017 petrochemical safety system intrusion
Atlas incident case studies
- TRITON / TRISIS2017 · Oil & Gas / Petrochemical
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Keep safety controller key switches in RUN/PROGRAM-disabled outside approved changes
- Alert on any TriStation or safety-network traffic from a non-approved host
- Isolate the SIS network from the BPCS and from any remote access
- Monitor engineering workstations that can reach the safety network as tier-0 assets
Hunt for this activity
- Unexpected engineering workstation peerAn engineering workstation is communicating with a system outside its normal peer set.
- Protocol use from an unexpected Purdue levelAn industrial protocol is being used across a Purdue boundary where it should not appear.
- Unexpected controller write or programming behaviourA controller received a write or programming operation that does not match an approved change.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- GovernmentCISAMAR-17-352-01 HatMan — Safety System Targeted Malware (opens in a new tab)
- Vendor IntelligenceGoogle Threat Intelligence / MandiantTRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers (opens in a new tab)
- ATT&CKMITRE ATT&CKTEMP.Veles (G0088) (opens in a new tab)
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)