Cyber Threat Actor: Xenotime
| Actor Type | Location | Known Incidents |
Nation State
|
Russia
|
0 incidents |
|---|
Profile
Xenotime is a threat actor group that operates under the alias Xenotime and is known to be based in Russia. The group has been observed in multiple public reports linking its activity to Russian cyber operations. It is recognized by security researchers as a distinct cluster that focuses on industrial control environments. The alias appears in threat intelligence feeds alongside other designations used for the same activity set. Public attributions consistently tie the group to Russian infrastructure. No other aliases are widely reported in open sources.
Xenotime primarily targets organizations in the energy and petrochemical sectors, with a particular focus on facilities that operate safety instrumented systems. Its observed behavior includes the deployment of malware capable of manipulating safety controllers, which indicates an interest in both espionage and the potential to disrupt physical processes. The group has been observed using spear‑phishing emails as an initial access vector to gain footholds in corporate networks. After establishing persistence, Xenotime deploys custom malware designed to interact with Schneider Electric Triconex safety controllers, a family commonly referred to as Triton or Trisis. The tooling style shows a preference for living‑off‑the‑land binaries combined with specially crafted payloads that modify controller memory. In addition to Triton, the group has used legitimate administrative tools and remote access frameworks to move laterally within victim environments.
Attribution to a state nexus is frequently cited in public reports, with analysts linking Xenotime to Russian government‑backed cyber units, although the exact agency is not disclosed in open source material. The group’s most notable campaign is the 2017 Triton intrusion against a Saudi petrochemical plant, where the malware attempted to manipulate safety shutdown processes. This operation was widely reported by multiple cybersecurity firms and highlighted the danger of attacks on safety‑instrumented systems. Other publicly disclosed activity includes attempts to probe energy companies in Europe and North America, though fewer details are available for those incidents. The consistent focus on industrial control environments and the use of tailored malware underscore Xenotime’s role as a specialized threat actor.
