logo

Dragos-FrostyGoop-ICS-Malware-Intel-Brief.pdf

ID: 9e43f5c4-8374-484d-bc19-a2710b8baaba

STIX ID: report--9e43f5c4-8374-484d-bc19-a2710b8baaba

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2024-07-19

Last Modified Date: 2024-07-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dragos analyzes FrostyGoop, a Golang ICS-focused malware that uses Modbus TCP (port 502) to read and modify holding registers; the report links FrostyGoop to a confirmed January 2024 attack in Lviv, Ukraine that disrupted heating for 600+ buildings, details malware capabilities, configuration and network indicators, and provides OT-specific detection and mitigation guidance including SANS 5 critical controls.