BTC $104925.2538
ETH $2492.1534
XRP $2.1865
BNB $649.3462
SOL $152.4818
DOGE $0.1855
TRX $0.2783
ADA $0.6694
stETH $2488.9105
WBTC $104867.6828
HYPE $34.0726
SUI $3.2841
wstETH $3000.8532
LINK $14.0245
AVAX $20.6518
USDS $0.9982
LEO $9.0733
XLM $0.2657
BCH $406.8060
TON $3.1963
HBAR $0.1689
LTC $88.3156
WETH $2491.6922
weETH $2663.7251
DOT $4.0267
XMR $325.3966
BSC-USD $0.9989
BGB $4.6675
BTCB $104866.5844
WBT $31.4499
USDE $1.0012
PEPE $0.0000
PI $0.6261
AAVE $253.6203
UNI $6.1751
sUSDe $1.1773
TAO $374.9828
DAI $0.9989
OKB $51.8888
APT $4.7571
NEAR $2.4129
CRO $0.0975
CBBTC $104966.3037
ICP $5.0311
ONDO $0.8302
ETC $17.1878
JITOSOL $183.9665
BTC $104925.2538
ETH $2492.1534
XRP $2.1865
BNB $649.3462
SOL $152.4818
DOGE $0.1855
TRX $0.2783
ADA $0.6694
stETH $2488.9105
WBTC $104867.6828
HYPE $34.0726
SUI $3.2841
wstETH $3000.8532
LINK $14.0245
AVAX $20.6518
USDS $0.9982
LEO $9.0733
XLM $0.2657
BCH $406.8060
TON $3.1963
HBAR $0.1689
LTC $88.3156
WETH $2491.6922
weETH $2663.7251
DOT $4.0267
XMR $325.3966
BSC-USD $0.9989
BGB $4.6675
BTCB $104866.5844
WBT $31.4499
USDE $1.0012
PEPE $0.0000
PI $0.6261
AAVE $253.6203
UNI $6.1751
sUSDe $1.1773
TAO $374.9828
DAI $0.9989
OKB $51.8888
APT $4.7571
NEAR $2.4129
CRO $0.0975
CBBTC $104966.3037
ICP $5.0311
ONDO $0.8302
ETC $17.1878
JITOSOL $183.9665
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • New 'FrostyGoop' malware for ICS systems detected, targets critical infrastructure

    In early January 2024, a devastating cyberattack on a local energy company took place in the Ukrainian city of Lviv. Cybersecurity researchers have discovered a ninth malware targeting industrial control systems (ICS). The new malware, dubbed FrostyGoop, is the first to use Modbus TCP communication to sabotage operational technology (OT) networks.

    Dragos, an industrial cybersecurity company, discovered FrostyGoop in April 2024. According to their data, this malware, written in the Golang language, is able to communicate with industrial control systems via port 502 using the Modbus TCP protocol.

    FrostyGoop has a wide range of capabilities, including reading and writing data to ICS devices, processing Modbus commands, and logging. The main target of this malware was ENCO controllers that have TCP port 502 open to the Internet.

    The incident led to the loss of heating services in more than 600 apartment buildings for almost two days. According to the researchers, the attackers sent Modbus commands to the ENCO controllers, which caused inaccurate measurements and system malfunctions. Initial access was likely gained by exploiting a vulnerability in Mikrotik routers in April 2023.

    Although FrostyGoop makes extensive use of the Modbus protocol, it is not the only example of such malware. In 2022, Dragos and Mandiant described another ICS malware called PIPEDREAM, which also used various industrial networking protocols.

    The ability of malware to read or modify data on ICS devices using Modbus poses a serious threat to industrial operations and public safety. Dragos notes that more than 46,000 ICS devices available on the Internet communicate using this protocol.

    The researchers emphasize the importance of implementing comprehensive cybersecurity systems to protect critical infrastructure from similar threats in the future.

    Global scam by Stargazer Goblin: 3,000 fake GitHub accounts spreading malware
    Top 10 Emerging Cybercrime Methods in 2024

    Comments 0

    Add comment