FrostyGoop malware attack cut off heat in Ukraine during winter
ID: 40d38aed-d2c2-5186-8f5c-8c60ce5d1593
STIX ID: report--40d38aed-d2c2-5186-8f5c-8c60ce5d1593
Feed Name: Bleeping Computer
FrostyGoop, an ICS-targeting Windows malware linked to Russian actors, was used in January 2024 to disable heating across over 600 apartment buildings in Lviv—affecting roughly 100,000 people. Attackers are reported to have breached a MikroTik router in April 2023, maintained persistence via a webshell, accessed the network via L2TP from Moscow, exploited poor network segmentation to control Modbus-based heating controllers, and downgraded firmware to evade detection; Dragos and Ukraine's CSSC have attributed the incident and urged ICS security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
