Dragos
Impact of FrostyGoop ICS Malware on Operational Technology Systems
Pages
13
Time to read
21 mins
Publication
Language
English
Pages
13
Time to read
21 mins
Publication
Language
English
This technical report details the FrostyGoop ICS malware, identified as the ninth industrial control system-specific malware, which utilizes Modbus TCP communications to affect operational technology (OT). Discovered by Dragos in April 2024, FrostyGoop can directly interact with ICS devices using Modbus, a widely used protocol across industrial sectors. The report outlines a significant cyber attack on a district energy company in Lviv, Ukraine, where FrostyGoop was implicated, leading to a two-day disruption of heating services for over 600 buildings. The malware's capabilities include reading and writing to ICS device holding registers and executing commands via configuration files. The report emphasizes the urgent need for enhanced ICS network visibility and monitoring to detect anomalies in Modbus traffic. It also recommends implementing the SANS 5 Critical Controls for robust OT cybersecurity, highlighting the necessity for continuous monitoring and risk management to mitigate such threats effectively.