ATT&CKCampaignsFrostyGoop Incident

FrostyGoop Incident

C0041

Campaign, Jan 2024 to Jan 2024.View on attack.mitre.org

About this campaign

FrostyGoop Incident took place in January 2024 against a municipal district heating company in Ukraine. Following initial access via likely exploitation of external facing services, FrostyGoop was used to manipulate ENCO control systems via legitimate Modbus commands to impact the delivery of heating services to Ukrainian civilians.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1003.002
Security Account Manager

During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture.

T1071
Application Layer Protocol

During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses.

T1190
Exploit Public-Facing Application

FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router.

T1505.003
Web Shell

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

T1689
Downgrade Attack

During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software0

None recorded.

References2

  1. Dragos FROSTYGOOP 2024 Open source
    Mark Graham, Carolyn Ahlers, Kyle O'Meara; Dragos. (2024, July). Impact of FrostyGoop ICS Malware on Connected OT Systems. Retrieved November 20, 2024.
  2. Nozomi BUSTLEBERM 2024 Open source
    Nozomi Networks Labs. (2024, July 24). Cyberwarfare Targeting OT: Protecting Against FrostyGoop/BUSTLEBERM Malware. Retrieved November 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.