Dragos-FrostyGoop-ICS-Malware-Intel-Brief.pdf
ID: 9e43f5c4-8374-484d-bc19-a2710b8baaba
STIX ID: report--9e43f5c4-8374-484d-bc19-a2710b8baaba
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2024-07-19
Last Modified Date: 2024-07-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dragos analyzes FrostyGoop, a Golang ICS-focused malware that uses Modbus TCP (port 502) to read and modify holding registers; the report links FrostyGoop to a confirmed January 2024 attack in Lviv, Ukraine that disrupted heating for 600+ buildings, details malware capabilities, configuration and network indicators, and provides OT-specific detection and mitigation guidance including SANS 5 critical controls.
