What is FrostyGoop?
FrostyGoop is malware for industrial control systems that sends commands to control devices via Modbus TCP, and which in January 2024 left more than 600 apartment buildings at a heating company in Lviv (Ukraine) without heating for two days in sub-zero temperatures. Dragos discovered the malware in April 2024 and published it in July 2024. FrostyGoop is the ninth known ICS-specific malware and the first to use Modbus TCP to cause physical impact. That is worrying, because Modbus is used in hundreds of thousands of installations worldwide, often without any security.
ποΈ How did the attack unfold?
| When | Event |
|---|---|
| April 2023 | Possible initial access through a vulnerable internet-facing router |
| 22β23 January 2024 | Attack on the heating company; heating fails in around 600 buildings |
| About two days | Recovery; residents are without heating in freezing weather |
| April 2024 | Dragos finds the malware during routine analysis of suspicious files |
| July 2024 | Analysis published |
π§ How did FrostyGoop work?
- The attackers probably entered through a vulnerable router at the network edge
- The network was not segmented: the controllers were directly reachable from the router
- The malware, written in Go, reads a configuration file containing IP addresses and Modbus registers
- It sends Modbus write commands to ENCO controllers, which drive the heating boilers
- The controllers report incorrect measurements and fail; heat supply stops
No vulnerability in the controllers was exploited: Modbus has no authentication, so any device that can reach the network may issue commands.
π How does FrostyGoop compare with other ICS malware?
| Malware | Year | Target | Protocol / method |
|---|---|---|---|
| Stuxnet | 2010 | Uranium enrichment (Iran) | Siemens S7, PLC reprogramming |
| Industroyer | 2016 | Power grid (Ukraine) | IEC 60870-5-104, IEC 61850 |
| TRITON | 2017 | Safety system (Saudi Arabia) | TriStation |
| PIPEDREAM | 2022 | Found before deployment | CODESYS, Omron FINS, OPC UA |
| FrostyGoop | 2024 | District heating (Ukraine) | Modbus TCP |
π― What lessons can you draw from FrostyGoop?
- No controller directly reachable from the internet β nor from the router that brings the internet in
- Network segmentation following the zones and conduits model, with an industrial firewall that can filter Modbus write commands (Protocol Filtering)
- Maintain edge devices β patch routers and VPNs and replace default passwords
- OT network monitoring that recognises anomalous Modbus commands
- Manual fallback β can boilers and pumps be operated locally if the control system fails?
π§ Why is Modbus so vulnerable?
Modbus was developed by Modicon in 1979 for serial communication in a closed plant. Security played no role at the time. Modbus TCP brought the same protocol to Ethernet in 1999, without adding security:
| Property | Consequence |
|---|---|
| No authentication | Any device on the network may read and write |
| No encryption | Traffic can be read and manipulated (Man-In-The-Middle) |
| No integrity check | Altered commands cannot be recognised |
| Simple structure | Attack tools are easy to build, as FrostyGoop shows |
A secure variant exists, Modbus/TCP Security (with TLS), but it is still poorly supported. Because thousands of Modbus devices are directly reachable from the internet, network-level isolation is the most important defence.
β Frequently asked questions
What exactly did FrostyGoop do?
FrostyGoop sent commands via Modbus TCP to ENCO controllers at a heating company in Lviv. The controllers then reported incorrect measurements and failed, cutting heating to more than 600 apartment buildings. In January 2024, residents were without heating for about two days in sub-zero temperatures.
Who was behind FrostyGoop?
The makers of FrostyGoop have not been officially named. Dragos linked the malware to the Lviv attack with moderate confidence, but made no firm attribution. Given the target, a Ukrainian energy company during Russiaβs war against Ukraine, a Russia-linked actor is widely considered likely.
Can FrostyGoop be used outside Ukraine?
Yes, FrostyGoop can in principle address any Modbus TCP device reachable over the network. The malware is not tied to one brand: the configuration file determines which devices and registers are attacked. Dragos warned that tens of thousands of Modbus devices worldwide are reachable from the internet.
How do you detect an attack like FrostyGoop?
An attack like FrostyGoop can be detected with OT network monitoring that analyses Modbus traffic. Signs include write commands from unknown IP addresses, commands to unusual registers or at unusual times, and sudden changes in process measurements. A baseline of normal traffic makes deviations visible.
What is the difference between FrostyGoop and Industroyer?
Industroyer attacked the Ukrainian power grid in 2016 using protocols from the energy sector, such as IEC 60870-5-104 and IEC 61850. FrostyGoop attacked a heating company in 2024 using Modbus TCP, a protocol found in virtually every sector. This gives FrostyGoop a larger potential reach.
What are ENCO controllers?
ENCO controllers are industrial controllers from the Turkish company ENCO Control, used among other things to control boilers and pumps in district heating networks. In the Lviv attack, FrostyGoop sent commands to these controllers via Modbus TCP. The attack did not exploit a vulnerability in the controllers themselves, but the absence of authentication in Modbus.
π In summary
FrostyGoop is ICS malware that manipulated controllers via Modbus TCP and, in January 2024, left more than 600 buildings in Lviv without heating in freezing weather. The attack exploited no vulnerability, but rather the lack of segmentation and the absence of authentication in Modbus.
