FrostyGoop
FrostyGoop とは何ですか?
FrostyGoopAn ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility.
FrostyGoop is an ICS-specific malware first publicly reported by Dragos in July 2024 and described as the ninth known piece of malware purpose-built to interact with industrial control systems. It is a Go binary designed to send Modbus TCP commands directly to industrial devices — most notably the ENCO heating controllers used at a Ukrainian district-heating utility in Lviv. In a January 2024 incident, FrostyGoop was used to send malicious Modbus TCP `write_multiple_registers` commands that altered controller setpoints, cutting heat for approximately 600 apartment buildings during winter for nearly two days. The malware's design assumes the attacker has already gained access to the engineering network; defenses are therefore concentrated upstream — robust IT/OT segmentation, removal of MikroTik-style edge devices with default credentials (the entry vector in the Lviv case), monitoring for unusual Modbus TCP write commands, and protocol-aware detection from OT-specific NDRs (Dragos, Claroty, Nozomi).
● 例
- 01
The January 2024 attack on Lviv's Lvivteploenergo heating utility used FrostyGoop to drive ENCO controllers to send heating-setpoint commands that interrupted service for ~600 apartment blocks.
- 02
An OT NDR rule alerts on `write_multiple_registers` from a non-engineering host to ENCO controllers — a behavior consistent with FrostyGoop.
● よくある質問
FrostyGoop とは何ですか?
An ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility. サイバーセキュリティの OT / ICS / IoT カテゴリに属します。
FrostyGoop とはどういう意味ですか?
An ICS-specific malware discovered by Dragos in 2024 that abuses Modbus TCP to disrupt energy and heating control systems, attributed by Dragos to a Russia-linked actor and tied to a January 2024 attack on a Ukrainian municipal heating utility.
FrostyGoop はどのように機能しますか?
FrostyGoop is an ICS-specific malware first publicly reported by Dragos in July 2024 and described as the ninth known piece of malware purpose-built to interact with industrial control systems. It is a Go binary designed to send Modbus TCP commands directly to industrial devices — most notably the ENCO heating controllers used at a Ukrainian district-heating utility in Lviv. In a January 2024 incident, FrostyGoop was used to send malicious Modbus TCP `write_multiple_registers` commands that altered controller setpoints, cutting heat for approximately 600 apartment buildings during winter for nearly two days. The malware's design assumes the attacker has already gained access to the engineering network; defenses are therefore concentrated upstream — robust IT/OT segmentation, removal of MikroTik-style edge devices with default credentials (the entry vector in the Lviv case), monitoring for unusual Modbus TCP write commands, and protocol-aware detection from OT-specific NDRs (Dragos, Claroty, Nozomi).
FrostyGoop からどのように防御しますか?
FrostyGoop に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
FrostyGoop の別名は何ですか?
一般的な別名: FROSTYGOOP, Modbus TCP malware (Lviv)。
● 関連用語
- ot-iot№ 587
産業用制御システム (ICS)
産業プロセスを自動化・監視するシステムの総称で、SCADA、DCS、PLC、RTU、安全制御システムなどを含む。
- ot-iot№ 1083
SCADA
遠隔のフィールド機器からテレメトリを収集し、運転員が広域な工業プロセスを監視・操作できるようにする監視制御・データ収集システム。
- ot-iot№ 784
Modbus
PLC、RTU、フィールド機器のレジスタやコイルをポーリングする、シンプルで仕様公開された産業用プロトコル。シリアル (RTU/ASCII) と TCP に対応。
- ot-iot№ 588
Industroyer / CrashOverride
2016 年のウクライナ電力網攻撃で使用され、2022 年に Industroyer2 として更新されたモジュール型 ICS マルウェア。電力網のネイティブプロトコルを話し変電所を遮断できる。
- ot-iot№ 1229
Stuxnet
2010 年に明らかになった高度なワーム。Siemens 製 PLC を再プログラムしてイランのウラン濃縮遠心分離機を破壊し、米国とイスラエルの関与が広く指摘されている。
- ot-iot№ 854
制御技術 (OT)
工場、発電所、ユーティリティなどの物理プロセス・機器・インフラを監視・制御するハードウェアとソフトウェアの総称。