Palo Alto Networks' Unit 42 detailed FrostyGoop, a Go-based malware family built to interact directly with industrial control systems and used in an attack that knocked out heating for two days across more than 600 apartment buildings in Ukraine during sub-zero temperatures. The malware targeted ENCO control devices over Modbus TCP, sending malicious commands that led to inaccurate measurements and operational failures in the heating environment, underscoring its focus on OT disruption rather than conventional IT compromise.
The report said FrostyGoop supports Modbus read, write, and multi-write functions through command-line arguments or JSON configuration files, and includes anti-debugging checks against the Windows BeingDebugged flag in the PEB. Investigators also examined a related Go utility, go-encrypt.exe, which can encrypt and decrypt JSON files with AES-256 CFB and may have been used to hide FrostyGoop configuration data, although that link remains unconfirmed. Unit 42 said possible initial access vectors included an unconfirmed MikroTik router vulnerability and internet-exposed OT assets; exposed ENCO devices were observed with services such as Telnet, Modbus, web interfaces, and ENCO-specific ports accessible from the internet, while VirusTotal and infrastructure pivots tied FrostyGoop samples, go-encrypt.exe, and a task_test.json file to the same first-seen date and a sample configuration referencing an ENCO device in Romania.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The report states that Dragos discovered FrostyGoop in April 2024. This marks the malware's reported discovery prior to the later public technical analysis.
A FrostyGoop configuration file named task_test.json was first seen on VirusTotal, and pivoting from it led to FrostyGoop Windows executables and go-encrypt.exe with the same first-seen date. The sample configuration referenced an ENCO device in Romania.
FrostyGoop was used in a cyberattack on Ukrainian heating infrastructure, where adversaries sent malicious Modbus commands to ENCO control devices. The incident caused inaccurate measurements and operational malfunctions, leading to a two-day outage affecting more than 600 apartment buildings during sub-zero temperatures.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.