What is FrostyGoop?

FrostyGoop is malware for industrial control systems that sends commands to control devices via Modbus TCP, and which in January 2024 left more than 600 apartment buildings at a heating company in Lviv (Ukraine) without heating for two days in sub-zero temperatures. Dragos discovered the malware in April 2024 and published it in July 2024. FrostyGoop is the ninth known ICS-specific malware and the first to use Modbus TCP to cause physical impact. That is worrying, because Modbus is used in hundreds of thousands of installations worldwide, often without any security.


πŸ—“οΈ How did the attack unfold?

When Event
April 2023 Possible initial access through a vulnerable internet-facing router
22–23 January 2024 Attack on the heating company; heating fails in around 600 buildings
About two days Recovery; residents are without heating in freezing weather
April 2024 Dragos finds the malware during routine analysis of suspicious files
July 2024 Analysis published

πŸ”§ How did FrostyGoop work?

  1. The attackers probably entered through a vulnerable router at the network edge
  2. The network was not segmented: the controllers were directly reachable from the router
  3. The malware, written in Go, reads a configuration file containing IP addresses and Modbus registers
  4. It sends Modbus write commands to ENCO controllers, which drive the heating boilers
  5. The controllers report incorrect measurements and fail; heat supply stops

No vulnerability in the controllers was exploited: Modbus has no authentication, so any device that can reach the network may issue commands.


πŸ”„ How does FrostyGoop compare with other ICS malware?

Malware Year Target Protocol / method
Stuxnet 2010 Uranium enrichment (Iran) Siemens S7, PLC reprogramming
Industroyer 2016 Power grid (Ukraine) IEC 60870-5-104, IEC 61850
TRITON 2017 Safety system (Saudi Arabia) TriStation
PIPEDREAM 2022 Found before deployment CODESYS, Omron FINS, OPC UA
FrostyGoop 2024 District heating (Ukraine) Modbus TCP

🎯 What lessons can you draw from FrostyGoop?


🧠 Why is Modbus so vulnerable?

Modbus was developed by Modicon in 1979 for serial communication in a closed plant. Security played no role at the time. Modbus TCP brought the same protocol to Ethernet in 1999, without adding security:

Property Consequence
No authentication Any device on the network may read and write
No encryption Traffic can be read and manipulated (Man-In-The-Middle)
No integrity check Altered commands cannot be recognised
Simple structure Attack tools are easy to build, as FrostyGoop shows

A secure variant exists, Modbus/TCP Security (with TLS), but it is still poorly supported. Because thousands of Modbus devices are directly reachable from the internet, network-level isolation is the most important defence.


❓ Frequently asked questions

What exactly did FrostyGoop do?

FrostyGoop sent commands via Modbus TCP to ENCO controllers at a heating company in Lviv. The controllers then reported incorrect measurements and failed, cutting heating to more than 600 apartment buildings. In January 2024, residents were without heating for about two days in sub-zero temperatures.

Who was behind FrostyGoop?

The makers of FrostyGoop have not been officially named. Dragos linked the malware to the Lviv attack with moderate confidence, but made no firm attribution. Given the target, a Ukrainian energy company during Russia’s war against Ukraine, a Russia-linked actor is widely considered likely.

Can FrostyGoop be used outside Ukraine?

Yes, FrostyGoop can in principle address any Modbus TCP device reachable over the network. The malware is not tied to one brand: the configuration file determines which devices and registers are attacked. Dragos warned that tens of thousands of Modbus devices worldwide are reachable from the internet.

How do you detect an attack like FrostyGoop?

An attack like FrostyGoop can be detected with OT network monitoring that analyses Modbus traffic. Signs include write commands from unknown IP addresses, commands to unusual registers or at unusual times, and sudden changes in process measurements. A baseline of normal traffic makes deviations visible.

What is the difference between FrostyGoop and Industroyer?

Industroyer attacked the Ukrainian power grid in 2016 using protocols from the energy sector, such as IEC 60870-5-104 and IEC 61850. FrostyGoop attacked a heating company in 2024 using Modbus TCP, a protocol found in virtually every sector. This gives FrostyGoop a larger potential reach.

What are ENCO controllers?

ENCO controllers are industrial controllers from the Turkish company ENCO Control, used among other things to control boilers and pumps in district heating networks. In the Lviv attack, FrostyGoop sent commands to these controllers via Modbus TCP. The attack did not exploit a vulnerability in the controllers themselves, but the absence of authentication in Modbus.


πŸ“Œ In summary

FrostyGoop is ICS malware that manipulated controllers via Modbus TCP and, in January 2024, left more than 600 buildings in Lviv without heating in freezing weather. The attack exploited no vulnerability, but rather the lack of segmentation and the absence of authentication in Modbus.