FrostyGoop malware attack cut off heat in Ukraine during winter

Share:

Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures.

According to an LB.UA report, the attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv’s Sykhiv residential area.

FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

It was first discovered by cybersecurity company Dragos in April 2024, whose researchers initially believed it was still under testing. However, Ukraine’s Cyber Security Situation Center (CSSC) shared details that the malware was being used in attacks and linked it with the January heating outage in Lviv.

“During the late evening on 22 January 2024, through 23 January, adversaries conducted a disruption attack against a municipal district energy company in Lviv, Ukraine,” said Dragos, based on information shared by the CSSC.

“At the time of the attack, this facility fed over 600 apartment buildings in the Lviv metropolitan area, supplying customers with central heating. Remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.”

FrostyGoop is the ninth ICS malware discovered in the wild, many of which are linked to Russian threat groups and attack infrastructure. Most recently, Mandiant discovered CosmicEnergy, and ESET spotted Industroyer2 being used by Sandworm hackers to target a large Ukrainian energy provider in a failed attack.

Network was breached almost one year earlier

An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo’s network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router.

Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive.

On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company’s network assets.

Since Lvivteploenergo’s network, including the compromised MikroTik router, four management servers, and the district’s heating system controllers, was not correctly segmented, they could exploit hardcoded network routes and take control of the district’s heating system controllers.

After hijacking them, the attackers downgraded the firmware to versions lacking monitoring capabilities to evade detection.

“Given the ubiquity of the Modbus protocol in industrial environments, this malware can potentially cause disruptions across all industrial sectors by interacting with legacy and modern systems,” Dragos warned.

The company advises industrial organizations to implement the SANS 5 Critical Controls for World-Class OT Cybersecurity, including “ICS incident response, defensible architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management.”

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:53 am, Jun 20, 2025
weather icon 17°C
L: 16° | H: 18°
broken clouds
Humidity: 83 %
Pressure: 1024 mb
Wind: 8 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 63%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 18°°C 0 mm 0% 11 mph 78 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 32°°C 0.21 mm 21% 11 mph 62 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
18° | 26°°C 1 mm 100% 14 mph 82 % 1016 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 25°°C 0.2 mm 20% 14 mph 75 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 15 mph 76 % 1017 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 7 mph 78 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
22° | 24°°C 0 mm 0% 8 mph 57 % 1024 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 33 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 11 mph 34 % 1022 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 10 mph 40 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 7 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 62 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 59 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,009.41
-0.32%
Ethereum(ETH)
€2,190.84
-0.10%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.88
-0.15%
Solana(SOL)
€126.74
-0.35%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.147315
-0.74%
Shiba Inu(SHIB)
€0.000010
-0.67%
Pepe(PEPE)
€0.000009
-1.82%
Scroll to Top