logo

Simple ‘FrostyGoop’ malware responsible for turning off Ukrainians’ heat in January attack

ID: c7fa7ef5-efe6-5022-b415-f889c95c6df1

STIX ID: report--c7fa7ef5-efe6-5022-b415-f889c95c6df1

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2024-07-23

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

Dragos reported a Modbus-targeting ICS malware named FrostyGoop that caused heat outages for more than 600 apartment buildings in Ukraine for two days. The attackers reportedly gained initial access via a MikroTik router vulnerability, spent about 10 months establishing access and credentials, and connected from Moscow-based IP addresses before the outage; Dragos tracks the activity as TAT2024-24. Although described as technically simple and written in Go, FrostyGoop is notable as the first observed ICS malware using Modbus to create a physical disruption, illustrating growing risks to critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.