not MITRE’s ATT&CK Group
TEMP.Veles
How MITRE ATT&CK characterizes this group1: TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Motivation not classified from the public record.
We could not place this actor into a coarse motivation tier from ATT&CK’s intrusion-set type and description prose. That uncertainty is itself a finding — the tradecraft below is still cited; the “why” is a coverage gap. All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesNo techniques are recorded for this group in the ATT&CK snapshot below — the tradecraft heatmap is empty. That is an honest coverage gap (sparse / legacy / revoked group), never a claim that the actor does nothing.1
Arsenal
— named tools & malware ATT&CK attributes to this groupCampaign highlights
— attributed operations in the ATT&CK recordTriton Safety Instrumented System Attack — ATT&CK Campaign C0030
C0032 — ATT&CK Campaign C0032
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.