BTC $88035.6337
ETH $3249.7719
SOL $212.0182
BNB $625.7404
DOGE $0.3811
XRP $0.7080
stETH $3242.1564
ADA $0.5716
TRX $0.1879
TON $5.4715
AVAX $34.0098
wstETH $3852.6153
WBTC $87813.8091
WETH $3280.1312
SUI $3.2183
LINK $13.9827
BCH $433.6969
UNI $8.9654
DOT $5.3295
LEO $7.4008
NEAR $5.3607
APT $12.3730
PEPE $0.0000
weETH $3420.0226
LTC $77.1351
DAI $0.9993
CRO $0.1761
BSC-USD $0.9991
TAO $569.2308
I***** $8.8310
FET $1.3808
RENDER $7.2150
CAKE $1.9585
KAS $0.1386
ETC $22.8438
WIF $3.2695
FDUSD $1.0008
WBT $21.8183
POL $0.4009
STX $2.0242
USDE $1.0022
XMR $151.5203
XLM $0.1349
AAVE $179.7038
OKB $45.1647
IMX $1.3469
FIL $4.2361
BTC $88035.6337
ETH $3249.7719
SOL $212.0182
BNB $625.7404
DOGE $0.3811
XRP $0.7080
stETH $3242.1564
ADA $0.5716
TRX $0.1879
TON $5.4715
AVAX $34.0098
wstETH $3852.6153
WBTC $87813.8091
WETH $3280.1312
SUI $3.2183
LINK $13.9827
BCH $433.6969
UNI $8.9654
DOT $5.3295
LEO $7.4008
NEAR $5.3607
APT $12.3730
PEPE $0.0000
weETH $3420.0226
LTC $77.1351
DAI $0.9993
CRO $0.1761
BSC-USD $0.9991
TAO $569.2308
I***** $8.8310
FET $1.3808
RENDER $7.2150
CAKE $1.9585
KAS $0.1386
ETC $22.8438
WIF $3.2695
FDUSD $1.0008
WBT $21.8183
POL $0.4009
STX $2.0242
USDE $1.0022
XMR $151.5203
XLM $0.1349
AAVE $179.7038
OKB $45.1647
IMX $1.3469
FIL $4.2361
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • New 'FrostyGoop' malware for ICS systems detected, targets critical infrastructure

    In early January 2024, a devastating cyberattack on a local energy company took place in the Ukrainian city of Lviv. Cybersecurity researchers have discovered a ninth malware targeting industrial control systems (ICS). The new malware, dubbed FrostyGoop, is the first to use Modbus T***** communication to sabotage operational technology (OT) networks.

    Dragos, an industrial cybersecurity company, discovered FrostyGoop in April 2024. According to their data, this malware, written in the Golang language, is able to communicate with industrial control systems via port 502 using the Modbus T***** protocol.

    FrostyGoop has a wide range of capabilities, including reading and writing data to ICS devices, processing Modbus commands, and logging. The main target of this malware was ENCO controllers that have T***** port 502 open to the Internet.

    The incident led to the loss of heating services in more than 600 apartment buildings for almost two days. According to the researchers, the attackers sent Modbus commands to the ENCO controllers, which caused inaccurate measurements and system malfunctions. Initial access was likely gained by exploiting a vulnerability in Mikrotik routers in April 2023.

    Although FrostyGoop makes extensive use of the Modbus protocol, it is not the only example of such malware. In 2022, Dragos and Mandiant described another ICS malware called PIPEDREAM, which also used various industrial networking protocols.

    The ability of malware to read or modify data on ICS devices using Modbus poses a serious threat to industrial operations and public safety. Dragos notes that more than 46,000 ICS devices available on the Internet communicate using this protocol.

    The researchers emphasize the importance of implementing comprehensive cybersecurity systems to protect critical infrastructure from similar threats in the future.

    Global scam by Stargazer Goblin: 3,000 fake GitHub accounts spreading malware
    Top 10 Emerging Cybercrime Methods in 2024

    Comments 0

    Add comment