Skip to main content
OT Atlas

Threats · Activity group

XENOTIME

unknownStage 2 ICS effectsDragosAttribution · High
Last verified

Executive summary

XENOTIME is the Dragos activity group associated with the TRITON / TRISIS intrusion, in which malware was written to interact with Schneider Electric Triconex safety instrumented systems at a petrochemical facility. It is the only publicly reported activity group whose capability was aimed directly at a safety instrumented system.

Publicly associated reporting tracks closely related activity as TEMP.Veles. Subsequent reporting has described interest in electric utilities in North America and elsewhere, expanding the sector concern beyond oil and gas.

At a glance

Tracked byDragos
NexusReported by the US government as linked to a Russian state research institute
First observed2017
Last reportedContinued vendor reporting of interest in electric utilities
ICS kill chainStage 1 — Intrusion · Stage 2 — Develop ICS capability · Stage 2 — Execute ICS attack

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

XENOTIME
  • TEMP.Veles
    Associated activityHigh

    Tracked by Google Threat Intelligence / Mandiant

  • TRITON / TRISIS
    Capability / malware nameConfirmed

    Tracked by Mandiant / Dragos — Malware naming, not an actor alias.

  • HatMan
    Capability / malware nameConfirmed

    Tracked by CISA

Relevance

Why OT defenders care

Objectives

  • Interaction with safety instrumented systems
  • Capability development against safety controllers
  • Persistent access to process environments

Reported impacts

  • Safety controllers entered a failsafe state and tripped the plant
  • Loss of safety function was the assessed potential outcome

Observed behaviours

  • Long dwell in the IT and DMZ environments before reaching the safety network
  • Use of an engineering workstation as the pivot to the safety controller
  • Direct interaction with safety controller programming over the vendor protocol

Targeting

Sectors, geography and assets

Target industries

Oil and gasPetrochemicalElectric power

Target geography

Middle EastNorth America

Observed assets

Safety instrumented systemSafety controller (Triconex)Engineering workstationDCS server

Protocols in scope

TriStation (UDP/1502)Vendor engineering protocols

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • TRITON / TRISISFramework that reimplemented the TriStation protocol to reach safety controller firmware.
  • Custom backdoors and credential tools

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

  • Native Windows administration tooling

ATT&CK

Technique mapping

ATT&CK Enterprise

ATT&CK for ICS

History

Known campaigns and incidents

Reported campaigns

  • 2017 petrochemical safety system intrusion

Atlas incident case studies

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Keep safety controller key switches in RUN/PROGRAM-disabled outside approved changes
  • Alert on any TriStation or safety-network traffic from a non-approved host
  • Isolate the SIS network from the BPCS and from any remote access
  • Monitor engineering workstations that can reach the safety network as tier-0 assets

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.