Campaign, Jan 2024 to Jan 2024.View on attack.mitre.org
FrostyGoop Incident took place in January 2024 against a municipal district heating company in Ukraine. Following initial access via likely exploitation of external facing services, FrostyGoop was used to manipulate ENCO control systems via legitimate Modbus commands to impact the delivery of heating services to Ukrainian civilians.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture. |
| T1071 Application Layer Protocol |
During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses. |
| T1190 Exploit Public-Facing Application |
FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router. |
| T1505.003 Web Shell |
FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| T1689 Downgrade Attack |
During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment. |
MITRE does not attribute this campaign to a group.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.