FrostyGoop, also referred to as BUSTLEBERM, is an industrial control system malware family designed to interact directly with operational technology over Modbus TCP. It is notable as an ICS-specific malware used to achieve disruptive physical impact through legitimate Modbus communications rather than through destructive payloads or protocol exploitation. The malware is written in Go and compiled for Windows, and it supports direct communication with industrial devices that expose Modbus services.
FrostyGoop can read holding registers and issue single-register and multi-register write operations, allowing an operator to alter process values and device behavior on reachable Modbus-speaking equipment. It accepts execution parameters via command line or structured JSON configuration, including target connection details, Modbus function selection, register addresses, and timing controls. It can log results to the console and optionally to JSON output. Analysis has also identified debugger-evasion behavior through inspection of the Windows process environment.
The malware has been linked to a disruptive January 2024 attack on district heating infrastructure in Lviv, Ukraine, where malicious Modbus commands were sent to ENCO heating controllers. The operation caused inaccurate measurements, controller malfunction, and a heating outage lasting nearly two days that affected more than 600 apartment buildings during sub-zero weather. Reporting has associated the activity with Russian actors. FrostyGoop’s functionality is not limited to ENCO equipment; its use of generic Modbus operations means it can potentially target any internet-reachable or otherwise accessible industrial device that speaks Modbus TCP.
Investigative reporting indicates the intrusion likely benefited from weak network segmentation between externally exposed infrastructure, management systems, and heating controllers, enabling movement from initial access into OT. FrostyGoop underscores the risk posed by unauthenticated industrial protocols and by direct exposure of OT assets, particularly in sectors such as energy, building systems, and other critical infrastructure environments that rely on Modbus-enabled controllers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"FrostyGoop (Jan 2024) cut heating to 600+ buildings in Ukraine in winter."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modbus-focused ICS malware referenced as an example showing that attacks against industrial/building control systems can cause real-world operational disruption, including heating outages.
Industrial-control-system malware that uses legitimate Modbus write operations, making detection reliant on behavioral baselining rather than exploit signatures.
ICS malware or tooling used to directly issue Modbus commands against heating controllers, disrupting service for roughly 600 buildings.
ICS malware used against district-heating infrastructure in Lviv, Ukraine. It communicated directly over Modbus TCP with ENCO heating controllers to alter process values and falsify controller readings, causing operational disruption and loss of heat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.