Simple ‘FrostyGoop’ malware responsible for turning off Ukrainians’ heat in January attack
ID: c7fa7ef5-efe6-5022-b415-f889c95c6df1
STIX ID: report--c7fa7ef5-efe6-5022-b415-f889c95c6df1
Feed Name: CyberScoop
Dragos reported a Modbus-targeting ICS malware named FrostyGoop that caused heat outages for more than 600 apartment buildings in Ukraine for two days. The attackers reportedly gained initial access via a MikroTik router vulnerability, spent about 10 months establishing access and credentials, and connected from Moscow-based IP addresses before the outage; Dragos tracks the activity as TAT2024-24. Although described as technically simple and written in Go, FrostyGoop is notable as the first observed ICS malware using Modbus to create a physical disruption, illustrating growing risks to critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
