Hackers shut down heating in Ukrainian city with malware, researchers say
ID: 0ff1ebf5-d49d-55aa-8298-f9f4bedfa097
STIX ID: report--0ff1ebf5-d49d-55aa-8298-f9f4bedfa097
Feed Name: TechCrunch Security News
Dragos published analysis of FrostyGoop, an ICS-focused malware that was used in January 2024 to disrupt heating in Lviv, Ukraine, knocking out service to over 600 apartment buildings for nearly 48 hours; the attackers likely gained persistent access via an internet-exposed MikroTik router and manipulated ENCO heating controllers over Modbus to report false measurements. While the malware appears targeted and not broadly destructive, Dragos warns FrostyGoop could be reused against other internet-exposed Modbus devices (tens of thousands worldwide), and investigators found connections from Moscow-based IPs but did not attribute the operation to a specific group or nation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
