ATT&CKReferencesDragos FROSTYGOOP 2024

Dragos FROSTYGOOP 2024

Mark Graham, Carolyn Ahlers, Kyle O'Meara; Dragos. (2024, July). Impact of FrostyGoop ICS Malware on Connected OT Systems. Retrieved November 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples5

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture.

T1071
Application Layer Protocol
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses.

T1190
Exploit Public-Facing Application
CampaignFrostyGoop Incident

FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router.

T1505.003
Web Shell
CampaignFrostyGoop Incident

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

T1689
Downgrade Attack
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.