XENOTIME
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Aliases: ATK91, G0088, TEMP.Veles
XENOTIME is a state-sponsored threat actor, first identified in June 2017, that is distinguished by its unique focus on developing and deploying malware specifically designed to compromise industrial safety instrumented systems (SIS). The group is assessed with high confidence to be of Russian origin and associated with the Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM/CNIIHM), a Russian government-controlled research institution. XENOTIME's primary motivation is to enable disruptive and destructive attacks against critical infrastructure, with the explicit intent to cause physical damage and potentially loss of human life. This sets XENOTIME apart as the first publicly known threat actor to specifically target industrial safety systems for such catastrophic outcomes. The group operates under several aliases including TRITON, TRISIS, and HatMan, and is also tracked as ATK91, G0088, and TEMP.Veles.