FrostyGoop, also known as BUSTLEBERM, is industrial control system malware written in Go and compiled for Windows. Discovered in April 2024, it communicates directly with operational technology devices using Modbus TCP to read and manipulate holding registers containing process values and configuration data. Its functionality is generic to Modbus-capable equipment rather than restricted to a particular controller manufacturer.
FrostyGoop supports reading holding registers, writing individual registers, and writing multiple registers. Operators supply connection details, register operations, and timing parameters through command-line arguments or JSON configuration files. The malware can record communication results to the console or a JSON log. It incorporates an anti-debugging check of the Windows Process Environment Block. Its use of legitimate Modbus operations enables process manipulation without requiring exploitation of the target controller.
FrostyGoop was linked to the January 2024 disruption of municipal district heating in Lviv, Ukraine, which left more than 600 apartment buildings without heating for nearly two days during sub-zero temperatures. Attackers manipulated ENCO heating controllers, producing false temperature readings and operational malfunctions. The operation also involved controller firmware downgrades that impaired process monitoring; these were attacker actions rather than an established built-in malware capability. Although its documented operational use targeted district heating, FrostyGoop can interact with other industrial equipment implementing Modbus TCP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"FrostyGoop (Jan 2024) cut heating to 600+ buildings in Ukraine in winter."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in a 2024 attack against a Ukrainian municipal energy company. The attack manipulated ENCO controllers to report false temperature readings, undermining the reliability of data on which district-heating operational decisions depended.
Modbus-focused ICS malware referenced as an example showing that attacks against industrial/building control systems can cause real-world operational disruption, including heating outages.
Industrial-control-system malware that uses legitimate Modbus write operations, making detection reliant on behavioral baselining rather than exploit signatures.
ICS malware or tooling used to directly issue Modbus commands against heating controllers, disrupting service for roughly 600 buildings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.