FrostyGoop
Was ist FrostyGoop?
FrostyGoopAn ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility.
FrostyGoop is an ICS-specific malware first publicly reported by Dragos in July 2024 and described as the ninth known piece of malware purpose-built to interact with industrial control systems. It is a Go binary designed to send Modbus TCP commands directly to industrial devices — most notably the ENCO heating controllers used at a Ukrainian district-heating utility in Lviv. In a January 2024 incident, FrostyGoop was used to send malicious Modbus TCP `write_multiple_registers` commands that altered controller setpoints, cutting heat for approximately 600 apartment buildings during winter for nearly two days. The malware's design assumes the attacker has already gained access to the engineering network; defenses are therefore concentrated upstream — robust IT/OT segmentation, removal of MikroTik-style edge devices with default credentials (the entry vector in the Lviv case), monitoring for unusual Modbus TCP write commands, and protocol-aware detection from OT-specific NDRs (Dragos, Claroty, Nozomi).
● Beispiele
- 01
The January 2024 attack on Lviv's Lvivteploenergo heating utility used FrostyGoop to drive ENCO controllers to send heating-setpoint commands that interrupted service for ~600 apartment blocks.
- 02
An OT NDR rule alerts on `write_multiple_registers` from a non-engineering host to ENCO controllers — a behavior consistent with FrostyGoop.
● Häufige Fragen
Was ist FrostyGoop?
An ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility. Es gehört zur Kategorie OT / ICS / IoT der Cybersicherheit.
Was bedeutet FrostyGoop?
An ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility.
Wie funktioniert FrostyGoop?
FrostyGoop is an ICS-specific malware first publicly reported by Dragos in July 2024 and described as the ninth known piece of malware purpose-built to interact with industrial control systems. It is a Go binary designed to send Modbus TCP commands directly to industrial devices — most notably the ENCO heating controllers used at a Ukrainian district-heating utility in Lviv. In a January 2024 incident, FrostyGoop was used to send malicious Modbus TCP `write_multiple_registers` commands that altered controller setpoints, cutting heat for approximately 600 apartment buildings during winter for nearly two days. The malware's design assumes the attacker has already gained access to the engineering network; defenses are therefore concentrated upstream — robust IT/OT segmentation, removal of MikroTik-style edge devices with default credentials (the entry vector in the Lviv case), monitoring for unusual Modbus TCP write commands, and protocol-aware detection from OT-specific NDRs (Dragos, Claroty, Nozomi).
Wie schützt man sich gegen FrostyGoop?
Schutzmaßnahmen gegen FrostyGoop kombinieren typischerweise technische Kontrollen und operative Praktiken, wie in der Definition oben beschrieben.
Welche anderen Bezeichnungen gibt es für FrostyGoop?
Übliche alternative Bezeichnungen: FROSTYGOOP, Modbus TCP malware (Lviv).
● Verwandte Begriffe
- ot-iot№ 587
Industrielles Steuerungssystem (ICS)
Sammelbegriff für Systeme zur Automatisierung und Überwachung industrieller Prozesse, darunter SCADA, DCS, SPS, RTU und Sicherheitssteuerungen.
- ot-iot№ 1083
SCADA
Supervisory-Control-and-Data-Acquisition-Systeme, die Telemetrie aus entfernten Feldgeräten sammeln und Bedienern Überwachung und Steuerung großer Anlagen ermöglichen.
- ot-iot№ 784
Modbus
Einfaches, offen dokumentiertes Industrieprotokoll zum Abfragen von Registern und Spulen in SPS, RTUs und Feldgeräten — verfügbar über seriell (RTU/ASCII) und TCP.
- ot-iot№ 588
Industroyer / CrashOverride
Modulares ICS-Malware-Framework, eingesetzt 2016 gegen das ukrainische Stromnetz und 2022 als Industroyer2 wiederaufgetaucht — spricht native Netzprotokolle.
- ot-iot№ 1229
Stuxnet
Hochkomplexer Wurm aus dem Jahr 2010, der durch Umprogrammierung von Siemens-SPS Irans Urananreicherungszentrifugen sabotierte und den USA und Israel zugeschrieben wird.
- ot-iot№ 854
Operational Technology (OT)
Hardware und Software, die physische Prozesse, Geräte und Infrastrukturen wie Fabriken, Kraftwerke und Versorgungsunternehmen überwachen und steuern.