logo

Hackers shut down heating in Ukrainian city with malware, researchers say

ID: 0ff1ebf5-d49d-55aa-8298-f9f4bedfa097

STIX ID: report--0ff1ebf5-d49d-55aa-8298-f9f4bedfa097

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2024-07-23

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

Dragos published analysis of FrostyGoop, an ICS-focused malware that was used in January 2024 to disrupt heating in Lviv, Ukraine, knocking out service to over 600 apartment buildings for nearly 48 hours; the attackers likely gained persistent access via an internet-exposed MikroTik router and manipulated ENCO heating controllers over Modbus to report false measurements. While the malware appears targeted and not broadly destructive, Dragos warns FrostyGoop could be reused against other internet-exposed Modbus devices (tens of thousands worldwide), and investigators found connections from Moscow-based IPs but did not attribute the operation to a specific group or nation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.