FrostyGoop
MITRE ATT&CK: S1165 View on attack.mitre.org
Aliases: BUSTLEBERM
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- control-server, field-controller/rtu/plc/ied
- Profile updated
- 2026-07-07 15:02:07
Targeted industries: energy-and-utilities
Targeted regions: country_code:ua
Context
FrostyGoop is a Windows-based binary written in Golang that allows for interaction with industrial control system (ICS) equipment via Modbus TCP over port 502. FrostyGoop allows for reading and writing data to holding registers on targeted devices, manipulating the operation of systems for malicious purposes. FrostyGoop is associated with the FrostyGoop Incident in Ukraine.
Detection coverage
- 1 YARA rules
Malware & tools used
- Modify Parameter (attack-pattern)
- Monitor Process State (attack-pattern)
- Standard Application Layer Protocol (attack-pattern)
- Commonly Used Port (attack-pattern)
- Command-Line Interface (attack-pattern)
Used by threat actors
- FrostyGoop Incident (campaign)
Detection rules
- SIGNATURE_BASE_MAL_Go_Modbus_Jul24_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Frostygoop (report)
- dragos.com — Protect Against Frostygoop Ics Malware Targeting Operational Technology (report)
- Palo Alto Unit 42 — Frostygoop Malware Analysis (report)