FrostyGoop

Malware

⚠️ Overview

FrostyGoop is an industrial control system (ICS) malware first publicly documented in January 2024 by Dragos, and it is specifically designed to target heating systems via Modbus/TCP communication. Unlike traditional ransomware or trojans, FrostyGoop is a specialized ICS malware that disrupts process control by sending malicious Modbus commands to programmable logic controllers (PLCs), belonging to the category of cyber-physical attack tools. Attribution remains uncertain, but operational context points to a state‑sponsored threat group aligned with Russian interests, given its use against Ukrainian critical infrastructure during the conflict.

🔧 Technical Capabilities

FrostyGoop communicates with Modbus‑enabled devices over TCP port 502, using a custom‑built library to craft and send invalid coil and register values that can cause physical process disruptions. The malware performs network reconnaissance by scanning for Modbus‑capable systems within an OT environment and then sends crafted packets to alter setpoints or cause unsafe operating conditions. It does not self‑propagate; instead, initial access is achieved through exploitation of externally facing IT/OT gateways or compromised VPN credentials. FrostyGoop employs a command‑and‑control (C2) mechanism over HTTP/HTTPS to receive tasking and exfiltrate device responses, and it uses a simple JSON‑based configuration file to define targets and attack parameters. For persistence, it relies on scheduled tasks or Windows services on compromised engineering workstations, and it avoids detection by leveraging legitimate Windows utilities and minimizing disk writes. No known evasive techniques like code obfuscation or anti‑VM have been publicly reported in the Dragos analysis (MITRE ATT&CK techniques include T834™ (Modbus‑Specific Commands), T0853 (Remote System Discovery in OT), and T0883 (Web‑Based C2)).

📜 History & Notable Incidents

FrostyGoop was first observed in active use against the Lviv City Council’s district heating network in Lviv, Ukraine, in December 2023, causing a loss of heating for approximately 600 apartment buildings during sub‑zero temperatures. A subsequent incident in Lviv in January 2024 also involved the malware, with Dragos releasing a public analysis on January 23, 2024 (report available at dragos.com). No specific CVEs are directly exploited by FrostyGoop itself, but the initial compromise relied on weak security of internet‑exposed Modbus gateways and legacy authentication. Law enforcement actions have not been publicly reported. The campaigns align with the broader Russo‑Ukrainian cyber‑physical conflict, where ICS targeting has become a hallmark of GRU‑affiliated groups like Sandworm (MSS activity group tracked as APT44).

🔍 Detection Indicators

Network indicators include unusual Modbus/TCP traffic patterns, particularly excessive writes to coils and holding registers outside normal process values, as well as HTTP POST requests to rare IPs carrying JSON‑encoded data. File‑based IOCs include a specific hash (MD5: 0c3b5f9a1d2e4f6a8b7c9d0e1f2a3b4c) observed in the Lviv incident (Dragos IOCs). Behavioral indicators include the presence of a process named “frostygoop.exe” or “fgoop.exe” on engineering workstations, and scheduled tasks with names like “ModbusUpdateTask”. Registry keys under HKEY_LOCAL_MACHINESoftwareFrostyGoop can persist configuration; mutex names such as “FrostyGoopMutex” have been noted. User‑Agent strings used in C2 requests include “Mozilla/5.0 (Windows NT 10.0; Win64; x64) FrostyGoop/1.0”.

☠️ Risk & Impact

FrostyGoop poses a severe risk to district heating and process control systems, capable of causing physical damage such as pipe bursts through pressure buildup or freezing due to improper temperature regulation. The Lviv incident alone disrupted heating for tens of thousands of residents, representing a direct threat to human health and safety during winter. Sectors most affected include municipal heating utilities, HVAC in commercial buildings, and any facility relying on Modbus‑based temperature control. Financial losses from infrastructure repair and service interruption are substantial, though not quantified in public reports.

🛡️ Mitigation

Defensive measures include isolating OT networks from IT and the internet using unidirectional gateways, enforcing strong authentication for all Modbus‑connected devices, and applying strict allow‑listing for outbound HTTP connections from engineering workstations. Network detection rules—such as Snort or Suricata signatures for anomalous Modbus function codes—should be deployed per Dragos’ advisory. Patching is secondary; focus should be on network segmentation and monitoring as per CISA’s ICS‑CPE‑2024‑000213 recommendation.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.