logo

Threat Proliferation in ICS Cybersecurity: XENOTIME Now Targeting Electric Sector, in Addition to Oil and Gas

ID: 4931f9c3-01d1-5126-b4e6-391f9e5fb739

STIX ID: report--4931f9c3-01d1-5126-b4e6-391f9e5fb739

Feed Name: Dragos Blog

Threat Score
90/100

Date Published: 2019-06-14

Date Updated: 2026-04-27

...
...

**XENOTIME expansion and ICS risk:** Dragos reports that XENOTIME — the group behind the TRISIS destructive ICS malware — has expanded targeting beyond oil & gas into electric utilities, conducting persistent reconnaissance, network enumeration, and credential-stuffing attempts; the group has previously compromised vendors and targeted safety instrumented systems (SIS), demonstrating capability and intent to cause disruptive or destructive effects, so ICS operators should increase visibility, detection, incident response planning, and cross-sector collaboration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.