logo

How to Protect Against FrostyGoop: ICS Malware Targeting Operational Technology

ID: ba1716c9-9874-5cc7-9069-83f44fbb67d1

STIX ID: report--ba1716c9-9874-5cc7-9069-83f44fbb67d1

Feed Name: Dragos Blog

Threat Score
75/100

Date Published: 2024-07-23

Date Updated: 2026-04-27

...
...

Dragos discovered FrostyGoop, a Golang ICS malware that communicates over Modbus TCP (port 502) and can directly interact with ENCO controllers; Dragos assesses it was likely used in a disruptive attack on a Ukrainian district heating provider that caused a two-day loss of service. The malware evades many antivirus products, Dragos has published IOCs and platform detections, and the report recommends OT-native monitoring, asset inventory checks, network segmentation, and SANS ICS controls to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.