logo

FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications

ID: ca3f51a9-3857-50f1-9398-521b3d0c90fa

STIX ID: report--ca3f51a9-3857-50f1-9398-521b3d0c90fa

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2024-11-19

Date Updated: 2026-04-28

Author: Asher Davila and Chris Navarrete

...
...

Palo Alto Networks Unit 42 analyzed FrostyGoop/BUSTLEBERM, an OT-centric Golang malware that issues Modbus TCP commands to ENCO control devices and was tied to a real-world disruption of heating services for 600+ residential buildings in Ukraine; the report provides sample and network analysis, configuration and library indicators, go-encrypt tooling correlation, exposed ENCO device telemetry, and multiple SHA256 IoCs to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.