FrostyGoop malware attack cut off heat in Ukraine during winter

Teilen:

Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures.

According to an LB.UA report, the attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv’s Sykhiv residential area.

FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

It was first discovered by cybersecurity company Dragos in April 2024, whose researchers initially believed it was still under testing. However, Ukraine’s Cyber Security Situation Center (CSSC) shared details that the malware was being used in attacks and linked it with the January heating outage in Lviv.

“During the late evening on 22 January 2024, through 23 January, adversaries conducted a disruption attack against a municipal district energy company in Lviv, Ukraine,” said Dragos, based on information shared by the CSSC.

“At the time of the attack, this facility fed over 600 apartment buildings in the Lviv metropolitan area, supplying customers with central heating. Remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.”

FrostyGoop is the ninth ICS malware discovered in the wild, many of which are linked to Russian threat groups and attack infrastructure. Most recently, Mandiant discovered CosmicEnergy, and ESET spotted Industroyer2 being used by Sandworm hackers to target a large Ukrainian energy provider in a failed attack.

Network was breached almost one year earlier

An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo’s network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router.

Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive.

On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company’s network assets.

Since Lvivteploenergo’s network, including the compromised MikroTik router, four management servers, and the district’s heating system controllers, was not correctly segmented, they could exploit hardcoded network routes and take control of the district’s heating system controllers.

After hijacking them, the attackers downgraded the firmware to versions lacking monitoring capabilities to evade detection.

“Given the ubiquity of the Modbus protocol in industrial environments, this malware can potentially cause disruptions across all industrial sectors by interacting with legacy and modern systems,” Dragos warned.

The company advises industrial organizations to implement the SANS 5 Critical Controls for World-Class OT Cybersecurity, including “ICS incident response, defensible architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:45 am, Jan. 21, 2025
Wetter-Symbol 4°C
L: 2° | H: 5°
overcast clouds
Luftfeuchtigkeit: 91 %
Druck: 1017 mb
Wind: 6 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:53 am
Sonnenuntergang: 4:29 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
2° | 5°°C 0 mm 0% 4 mph 94 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 5°°C 0.2 mm 20% 8 mph 96 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 14 mph 88 % 1007 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
5° | 11°°C 1 mm 100% 23 mph 91 % 1006 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
3° | 6°°C 1 mm 100% 10 mph 83 % 1010 mb 0.8 mm/h
Today 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 92 % 1017 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 94 % 1016 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 93 % 1015 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 77 % 1015 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 73 % 1013 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 89 % 1012 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 94 % 1011 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 95 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,873.50
1.19%
Ethereum(ETH)
€3,120.14
2.07%
XRP(XRP)
€3.01
5.09%
Fesseln(USDT)
€0.96
-0.02%
Solana(SOL)
€228.88
-2.81%
Dogecoin(DOGE)
€0.336880
-0.20%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
1.04%
Pepe(PEPE)
€0.000015
0.93%
Peanut das Eichhörnchen(PNUT)
€0.367551
-3.79%
Nach oben scrollen