FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications
ID: ca3f51a9-3857-50f1-9398-521b3d0c90fa
STIX ID: report--ca3f51a9-3857-50f1-9398-521b3d0c90fa
Feed Name: Palo Alto Networks Unit 42
Threat Score
Palo Alto Networks Unit 42 analyzed FrostyGoop/BUSTLEBERM, an OT-centric Golang malware that issues Modbus TCP commands to ENCO control devices and was tied to a real-world disruption of heating services for 600+ residential buildings in Ukraine; the report provides sample and network analysis, configuration and library indicators, go-encrypt tooling correlation, exposed ENCO device telemetry, and multiple SHA256 IoCs to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
