logo

FrostyGoop malware attack cut off heat in Ukraine during winter

ID: 40d38aed-d2c2-5186-8f5c-8c60ce5d1593

STIX ID: report--40d38aed-d2c2-5186-8f5c-8c60ce5d1593

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-07-23

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

FrostyGoop, an ICS-targeting Windows malware linked to Russian actors, was used in January 2024 to disable heating across over 600 apartment buildings in Lviv—affecting roughly 100,000 people. Attackers are reported to have breached a MikroTik router in April 2023, maintained persistence via a webshell, accessed the network via L2TP from Moscow, exploited poor network segmentation to control Modbus-based heating controllers, and downgraded firmware to evade detection; Dragos and Ukraine's CSSC have attributed the incident and urged ICS security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.