Novel ICS Malware Sabotaged Water-Heating Services in Ukraine
ID: 857b1f45-13ba-5793-aec9-e7fa41733c2d
STIX ID: report--857b1f45-13ba-5793-aec9-e7fa41733c2d
Feed Name: Dark Reading
Dragos discovered FrostyGoop, a Golang Windows malware that directly manipulates ICS devices over Modbus TCP (port 502); it was used in a January 2024 incident that caused nearly 48 hours of cold water for ~600 Lviv apartments by altering controller registers and firmware. The report details the intrusion chain—initial compromise via an externally facing router and web shell, credential exfiltration, lateral movement due to poor network segmentation, and active commands sent to ENCO-branded heating controllers—and warns that ~46,000 internet-exposed Modbus devices are at risk, recommending segmentation, monitoring, secure remote access, vulnerability management, and incident response improvements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
